Friday, December 27, 2024
HomeCyber Security NewsIvanti Sentry Flaw: Let Attackers Access Critical APIs Used for Configuration

Ivanti Sentry Flaw: Let Attackers Access Critical APIs Used for Configuration

Published on

SIEM as a Service

An unauthenticated critical API access vulnerability was found in the Ivanti Sentry interface, which could allow a threat actor to gain access to sensitive APIs that can be used to access the Ivanti administrator portal and configure Ivanti Sentry.

This vulnerability can also be used to execute OS commands on the 

If an attacker succeeds in exploitation, the attacker will be able to configure Ivnati Sentry, execute system commands, or write files onto the system.

- Advertisement - SIEM as a Service

However, since this administrator portal uses port 8443, users who do not have their Ivanti administrator portal exposed over the internet have a low ratio of exploitation.

CVE-2023-38035: API Authentication Bypass

This vulnerability exists due to insufficient restrictive Apache HTTPD configuration that allows a threat actor to bypass authentication controls on the administrator portal of Ivanti.

The CVSS score for this vulnerability is yet to be confirmed. Nonetheless, Ivanti Sentry has provided a CVSS score of 9.8 (Critical). 

“Exploitation is only possible through the System Manager Portal, hosted on port 8443 by default.” reads the Knowledge Base (KB) article of Ivanti. 

Ivanti Sentry, which was formerly known as MobileIron Sentry, is a Unified Endpoint Management product that can be used by organizations to encrypt, manage, decrypt, and protect mobile devices and backend systems traffic.

Ivanti confirmed in their security advisory that this vulnerability does not affect other Ivanti products like Ivanti EPMM or Ivanti Neurons for MDM. Ivanti Sentry products with versions 9.18, 9.17, 9.16, and older versions are affected by this vulnerability. 

For fixing this vulnerability, Ivanti has provided a resolution involving steps to remediate this vulnerability. Ivanti also recommended users restrict external access to the administrator portal at 8443, which can only be accessed by IT administrators or an internal management network.

Keep informed about the latest Cyber Security News by following us on GoogleNewsLinkedinTwitter, and Facebook.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Araneida Scanner – Hackers Using Cracked Version Of Acunetix Vulnerability Scanner

Threat Analysts have reported alarming findings about the "Araneida Scanner," a malicious tool allegedly...

A Dark Web Operation Acquiring KYC Details TO Bypass Identity Verification Systems

A major dark web operation dedicated to circumventing KYC (Know Your Customer) procedures, which...

Adobe Warns of ColdFusion Vulnerability Allows Attackers Read arbitrary files

Adobe has issued a critical security update for ColdFusion versions 2023 and 2021 to...

Beware of New Malicious PyPI packages That Steals Login Details

Two malicious Python packages, Zebo-0.1.0 and Cometlogger-0.1, were recently detected by Fortinet's AI-driven OSS...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Araneida Scanner – Hackers Using Cracked Version Of Acunetix Vulnerability Scanner

Threat Analysts have reported alarming findings about the "Araneida Scanner," a malicious tool allegedly...

A Dark Web Operation Acquiring KYC Details TO Bypass Identity Verification Systems

A major dark web operation dedicated to circumventing KYC (Know Your Customer) procedures, which...

Adobe Warns of ColdFusion Vulnerability Allows Attackers Read arbitrary files

Adobe has issued a critical security update for ColdFusion versions 2023 and 2021 to...