8.8
CVSSv3

CVE-2023-41724

Published: 31/03/2024 Updated: 01/04/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A command injection vulnerability in Ivanti Sentry before 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ivanti standalone sentry

Github Repositories

CVE-2023-41724 POC RCE Ivanti

CVE-2023-41724 CVE-2023-41724 POC RCE Ivanti

Recent Articles

Ivanti fixes critical Standalone Sentry bug reported by NATO
BleepingComputer • Sergiu Gatlan • 20 Mar 2024

Ivanti fixes critical Standalone Sentry bug reported by NATO By Sergiu Gatlan March 20, 2024 01:08 PM 0 Ivanti warned customers to immediately patch a critical severity Standalone Sentry vulnerability reported by NATO Cyber Security Centre researchers. Standalone Sentry is deployed as an organization's Kerberos Key Distribution Center Proxy (KKDCP) server or as a gatekeeper for ActiveSync-enabled Exchange and Sharepoint servers. Tracked as CVE-2023-41724, the security flaw impacts all supported ...