A vulnerability in Sentry allows attackers to create arbitrary administrator accounts without prior authentication, gaining full admin access.
| Vendor | Product | Versions |
|---|---|---|
| ivanti | sentry | 10.7.0 and below, 10.6.1 and below, 10.5.1 and below |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| ivanti | sentry | cert_advisory | 90% |
Updated description with more technical detail and confirmed severity and CVSS score.
Updated description with new details about the patch and added relevant tags.
Added affected versions 10.7.0 and below, 10.6.1 and below, 10.5.1 and below, and updated patch available versions to 10.7.1, 10.6.2, 10.5.2.
Updated description with new details about the ability to execute arbitrary code and marked the vulnerability as actively exploited with an exploit available.
Updated affected versions to R10.5.1, R10.6.1, R10.7.0 and noted that no exploit is available.
Initial creation