CVE-2024-8540: High severity ivanti sentry vulnerability
Published Dec 10, 2024
·Updated
Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.
Affected Software
3 affected components
Ivanti Sentry<9.20.2, <10.0.2, <10.1.0
Ivanti Standalone Sentry<9.20.2
Ivanti Standalone Sentry=10.0.1
Event History
Dec 10, 2024
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-8540?
CVE-2024-8540 is considered a high severity vulnerability due to its potential to allow local authenticated attackers to modify sensitive components in Ivanti Sentry.
2
How do I fix CVE-2024-8540?
To fix CVE-2024-8540, upgrade Ivanti Sentry to version 9.20.2 or later, or to version 10.0.2 or later.
3
Who is affected by CVE-2024-8540?
CVE-2024-8540 affects users of Ivanti Sentry running versions prior to 9.20.2, 10.0.2, or 10.1.0.
4
What components can be modified due to CVE-2024-8540?
CVE-2024-8540 allows local authenticated attackers to modify sensitive application components within Ivanti Sentry.
5
Is remote access required to exploit CVE-2024-8540?
No, CVE-2024-8540 requires local authenticated access to exploit the insecure permissions.