CVE-2023-41724
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
31/03/2024
Last modified:
01/08/2024
Description
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:* | 9.19.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



