Unauthorized Access Vulnerability in Ivanti's Sentry Product
CVE-2023-39338
6.8MEDIUM
What is CVE-2023-39338?
An authenticated user on an enrolled device can potentially exploit a vulnerability in Ivanti's Sentry product to gain unauthorized tunnel access to a protected service. While the user cannot authenticate or directly use the service, this exploit allows bypassing Sentry's access control policies, potentially exposing sensitive services to unauthorized access. Prompt remediation is required to mitigate risks associated with this vulnerability.
Affected Version(s)
Sentry 9.0 < 9.20