An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Ivanti Standalone_Sentry
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
|
— |
10.5.2
|
|
Ivanti Standalone_Sentry
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
|
10.6.0
|
10.6.2
|
|
Ivanti Standalone_Sentry
cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*
|
— | — |