First published: Sun Mar 31 2024(Updated: )
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
<9.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-41724 is classified as a critical severity vulnerability due to its potential for remote code execution.
To fix CVE-2023-41724, upgrade Ivanti Sentry to version 9.19.0 or higher.
CVE-2023-41724 affects all versions of Ivanti Standalone Sentry prior to 9.19.0.
Yes, CVE-2023-41724 can be exploited by unauthenticated attackers within the same network.
CVE-2023-41724 is a command injection vulnerability that allows execution of arbitrary commands.