CVE-2023-41724
Ivanti MobileIron Sentry Analyse et atténuation des vulnérabilités

Aperçu

A critical command injection vulnerability (CVE-2023-41724) was discovered in Ivanti Standalone Sentry, affecting versions prior to 9.19.0. The vulnerability was reported by researchers from the NATO Cybersecurity Centre. Ivanti Standalone Sentry is an appliance that functions as a gateway between devices and ActiveSync-enabled email servers or backend resources, and can also be configured as a Kerberos Key Distribution Center Proxy (KKDCP) server (Helpnet Security).

Détails techniques

CVE-2023-41724 has been assigned a CVSS score of 9.6 (Critical) with the vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The vulnerability allows an unauthenticated threat actor within the same physical or logical network to execute arbitrary commands on the appliance's operating system. Notably, threat actors without a valid TLS client certificate enrolled through EPMM cannot directly exploit this issue on the Internet (Ivanti Blog).

Impact

If successfully exploited, the vulnerability enables attackers to execute arbitrary commands on the underlying operating system of the Ivanti Standalone Sentry appliance, potentially leading to complete system compromise. The vulnerability affects all supported versions (9.17.0, 9.18.0, and 9.19.0) as well as older, unsupported versions (SOCRadar).

Atténuation et solutions de contournement

Ivanti has released patches to address the vulnerability. Users of supported versions should update to versions 9.17.1, 9.18.1, or 9.19.1. Organizations running versions older than 9.17.0 are advised to upgrade to a supported version and then apply the appropriate patch. The patches are available through Ivanti's standard download portal (Ivanti Blog).

Réactions de la communauté

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert urging users and administrators to patch these critical vulnerabilities, emphasizing the potential for threat actors to exploit them and gain control of affected systems (SOCRadar).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Ivanti MobileIron Sentry Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-10520CRITICAL10
  • Ivanti MobileIron SentryIvanti MobileIron Sentry
  • cpe:2.3:a:ivanti:mobileiron_sentry
OuiOuiJun 09, 2026
CVE-2026-10523CRITICAL9.9
  • Ivanti MobileIron SentryIvanti MobileIron Sentry
  • cpe:2.3:a:ivanti:mobileiron_sentry
NonOuiJun 09, 2026
CVE-2023-38035CRITICAL9.8
  • Ivanti MobileIron SentryIvanti MobileIron Sentry
  • cpe:2.3:a:ivanti:mobileiron_sentry
OuiOuiAug 21, 2023
CVE-2023-41724HIGH8.8
  • Ivanti MobileIron SentryIvanti MobileIron Sentry
  • cpe:2.3:a:ivanti:mobileiron_sentry
NonOuiMar 31, 2024
CVE-2020-15507HIGH7.5
  • NixOSNixOS
  • core
NonOuiJul 07, 2020

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités