Ivanti Sentry
- <= 10.5.1
- <= 10.6.1
- <= 10.7.0
This vulnerability is being actively exploited in the wild.
A command injection vulnerability has been identified in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. This vulnerability allows remote, unauthenticated users to execute code with root privileges on the affected system.
Exploitation of this vulnerability leads to unauthorized root-level access, allowing for remote code execution on the affected system.
Users can update to Ivanti Sentry versions 10.5.2, 10.6.2, or 10.7.1. The new versions are available on the Ivanti Support Portal, with detailed update instructions provided.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.