Skip to the content.

DIVD-2023-00034 - API Authentication Bypass Vulnerability in Ivanti Sentry

Our reference DIVD-2023-00034
Case lead Max van der Horst
Researcher(s)
CVE(s)
Products
  • Ivanti Sentry
  • MobileIron Sentry
Versions
  • All versions before 9.18.0.
Recommendation Limit access to port 8443 and install the RPM scripts given in Ivanti's Security Advisory.
Patch status Mitigated
Status Closed
Last modified 26 Sep 2023 09:39 CEST

Summary

A vulnerability has been discovered in Ivanti Sentry, formerly MobileIron Sentry. The vulnerability impacts all supported versions up until version 9.18. If exploited, this vulnerability enables an unauthenticated attacker to access sensitive API endpoints that are used to configure Ivanti Sentry on the administrator portal. There are also proof-of-concepts available that leverage the exposed API endpoints that lead to remote code execution (RCE) on the server. The risk can be mitigated by limiting access to port 8443 and installing the provided RPM scripts in the Security Advisory. This vulnerability is actively being exploited and therefore mitigation should be done as soon as possible.

Recommendations

Limit access to port 8443 on the administrator portal (known as MICS, MobileIron Configuration Service) and install the Ivanti-provided RPM scripts to mitigate the problem.

What we are doing

DIVD is scanning for vulnerable systems. Owners of such systems will receive a notification with this casefile and remediation steps.

Timeline

Date Description
22 Aug 2023 DIVD starts scanning for this vulnerability.
22 Aug 2023 First version of this casefile.
23 Aug 2023 First round of notifications sent.
02 Sep 2023 Second round of notificaitons sent.
03 Sep 2023 DIVD monitors decrease of vulnerable hosts.
26 Sep 2023 Case closed.
gantt title DIVD-2023-00034 - API Authentication Bypass Vulnerability in Ivanti Sentry dateFormat YYYY-MM-DD axisFormat %e %b %Y section Case DIVD-2023-00034 - API Authentication Bypass Vulnerability in Ivanti Sentry (35 days) :2023-08-22, 2023-09-26 section Events DIVD starts scanning for this vulnerability. : milestone, 2023-08-22, 0d First version of this casefile. : milestone, 2023-08-22, 0d First round of notifications sent. : milestone, 2023-08-23, 0d Second round of notificaitons sent. : milestone, 2023-09-02, 0d DIVD monitors decrease of vulnerable hosts. : milestone, 2023-09-03, 0d Case closed. : milestone, 2023-09-26, 0d

More information