• News/
  • https://www.bleepingcomputer.com/news/security/ivanti-fixes-critical-standalone-sentry-bug-reported-by-nato/

Ivanti fixes critical Standalone Sentry bug reported by NATO

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 20, 2024
·
Updated

Ivanti warned customers to immediately patch a critical severity Standalone Sentry vulnerability reported by NATO Cyber Security Centre researchers. Standalone Sentry is deployed as an organization's Kerberos Key Distribution Center Proxy (KKDCP) server or as a gatekeeper for ActiveSync-enabled Exchange and Sharepoint servers. Tracked as CVE-2023-41724, the security flaw impacts all supported versions and it allows unauthenticated bad actors within the same physical or logical network to execute arbitrary commands in low-complexity attacks. Ivanti also fixed a second critical vulnerability (CVE-2023-46808) in its Neurons for ITSM IT service management solution that enables remote threat actors with access to an account with low privileges to execute commands "in the context of web application's user." While this patch has already been applied to all Ivanti Neurons for ITSM Cloud landscapes, on-premises deployments are still vulnerable to potential attacks. The company added that it found no evidence that these two security vulnerabilities are being exploited in the wild. "There is a patch available now via the standard download portal. We strongly encourage customers to act immediately to ensure they are fully protected," Ivanti said. "We are not aware of any customers being exploited by this vulnerability at the time of disclosure." Since the start of the year, nation-state actors have exploited multiple Ivanti vulnerabilities as zero-days (i.e., CVE-2023-46805, CVE-2024-21...

Read full article

Affected Software

4 affected components
Ivanti Standalone Sentry
Ivanti Neurons for ITSM
Ivanti Connect Secure
Ivanti Policy Secure
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical security vulnerability in Ivanti's Standalone Sentry product that was reported by NATO and necessitates immediate patching.

2

What security implications are discussed?

The security implications include potential exploitation of the critical vulnerability which could compromise the security of organizations using Standalone Sentry as a Kerberos Key Distribution Center Proxy.

3

What products or software are affected?

The vulnerabilities impact Ivanti Standalone Sentry, Neurons for ITSM, Connect Secure, and Policy Secure.

4

Who reported the vulnerability to Ivanti?

The vulnerability was reported to Ivanti by NATO Cyber Security Centre researchers.

5

What action should Ivanti customers take in response to this article?

Ivanti customers are advised to immediately apply the provided patches to mitigate the risks associated with the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203