Identity CVE · Other
CVE-2023-38035Ivanti Sentry authentication bypass
criticalCISA KEVActively exploited
Product: Ivanti Sentry (MobileIron Sentry)Vendor: IvantiDisclosed: 2023-08-21Status: Actively exploitedNVD ↗CISA KEV ↗
What broke
Ivanti Sentry, the gateway that sits in front of EPMM / MobileIron, exposed an administrative API without authentication. CISA added CVE-2023-38035 to KEV. August 2023, weeks after CVE-2023-35078 on EPMM itself.
Why it matters
Sentry terminates device and app traffic and often holds the keys that talk to EPMM. An auth bypass on the gateway is how you skip the MDM you just patched. Ivanti's 2023-2025 record (EPMM, Sentry, Connect Secure, addUser) is one product family failing authentication over and over.
What to do
- Patch Sentry. If it was internet-facing in August 2023, review admin users and certificates it issued.
- Do not expose Sentry admin or its system API to the internet.
- Treat Ivanti appliances as one identity system: patch EPMM, Sentry, and Connect Secure on the same cadence.
Sources
- NVD: CVE-2023-38035
- CISA KEV
- Ivanti Sentry advisory, August 2023
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.