An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Standalone_sentry | Ivanti | * | 10.5.2 (excluding) |
| Standalone_sentry | Ivanti | 10.6.0 (including) | 10.6.2 (excluding) |
| Standalone_sentry | Ivanti | 10.7.0 (including) | 10.7.0 (including) |