Ivanti Sentry Authenticated User Access Vulnerability

Vulnerability

A vulnerability in Ivanti Sentry (formerly MobileIron Sentry) allows an authenticated user with an enrolled device to access services protected by Sentry, bypassing authorization policies. While the vulnerability creates a tunnel access to the service, it does not allow the user to authenticate or use the service directly. This issue affects all supported versions of Sentry, including 9.16, 9.17, and 9.18, as well as older releases.

Impact

Exploitation of this vulnerability could lead to unauthorized access to services protected by Sentry, allowing users to gain restricted capabilities.

Remediation

Users are advised to upgrade to Ivanti Sentry version 9.20, where this vulnerability has been patched. For detailed instructions on how to apply the update, refer to the Ivanti Knowledge Base article on this vulnerability.

Added: Jul 12, 2025, 4:21 AM
Updated: Jul 12, 2025, 4:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.3
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.