QID 731287

Date Published: 2024-03-21

QID 731287: Ivanti Standalone Sentry Remote Code Execution (RCE) Vulnerability

Ivanti Standalone Sentry is vulnerable to Remote Code Execution Vulnerability. An unauthenticated threat actor can execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.

Affected Versions:
Ivanti Standalone Sentry 9.17.0 Ivanti Standalone Sentry 9.18.0 Ivanti Standalone Sentry 9.19.0 Older versions of Ivanti Standalone Sentry are also at risk.

Patched Versions:
Ivanti Standalone Sentry 9.17.1
Ivanti Standalone Sentry 9.18.1
Ivanti Standalone Sentry 9.19.1

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Ivanti Standalone Sentry by sending an HTTP GET request to the 'mics/login.jsp' endpoint and extracting the version from the response received.

Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary commands on the underlying operating system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to upgrade to the latest version of Ivanti Standalone Sentry to address the vulnerability. For more information, please refer to the Ivanti Security Advisory

    CVEs related to QID 731287

    Software Advisories
    Advisory ID Software Component Link
    Ivanti Security Advisory URL Logo forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US