Ivanti Sentry
- <= 10.5.1
- <= 10.6.1
- <= 10.7.0
A vulnerability allowing authentication bypass has been identified in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. This vulnerability allows remote unauthenticated attackers to create arbitrary administrative accounts, granting them full administrative access.
Exploitation of this vulnerability allows for the creation of administrative accounts, providing full administrative privileges to the attacker.
Users can update to Ivanti Sentry versions 10.5.2, 10.6.2, or 10.7.1. The new versions can be downloaded from the Ivanti Download Portal (login required).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.