Impact
The flaw is an Authentication Bypass that allows a remote unauthenticated attacker to gain administrative level access to the Ivanti Sentry application. This weakness falls under CWE‑288, which represents problems in the authentication process that enable an attacker to bypass the intended access controls. The lack of authentication results in the attacker acquiring the full privileges of an administrator, giving them complete control over the system and its data. The impact is therefore a direct privilege escalation that can be leveraged for any number of subsequent attacks.
Affected Systems
Ivanti Sentry versions prior to R10.8.2, R10.7.3, and R10.6.4 are affected. Any deployment running those releases is vulnerable to the authentication bypass described above.
Risk and Exploitability
The CVSS score is 8.1, placing the vulnerability in the high severity range. The EPSS score is not available, but the lack of a KEV listing indicates that no known exploit has been documented in the CISA catalog. Attackers can exploit the flaw remotely without any authentication, which suggests that network exposure heightens risk. The high CVSS indicates significant potential for damage once the vulnerability is exploited.
OpenCVE Enrichment