CVE-2023-38035: Ivanti Sentry
EPSS99.9%No. 98 of 1739 in KEV
CVE year2023listed the same year
Same vendor in KEV35
Same product2
| Field | Value |
|---|---|
| Vendor | Ivanti |
| Product | Sentry |
| Name | Ivanti Sentry Authentication Bypass Vulnerability |
| Added to KEV | 2023-08-22 |
| US federal due date | 2023-09-12 |
| Ransomware use | Known |
| CWE | CWE-863 |
CISA description
Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-10520 | Ivanti Sentry | 2026-06-11 | 99.9% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Ivanti Sentry vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-08-22.