← back
CVE-2023-41724criticalobserved exploitationCWE-94

CVE-2023-41724

55Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.6epss 13%
from disclosure to weapon
Published on NVDMar 31
VulnCheck+44d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Ivanti · Sentry