CVE-2023-41724

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
31/03/2024
Last modified:
01/08/2024

Description

A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:* 9.19.0 (excluding)