R10.5.2, R10.6.2, R10.7.1 버전 이전 Ivanti Sentry의 OS 명령 주입 취약점으로 인해 인증되지 않은 원격 사용자가 루트 수준의 원격 코드 실행이 가능해졌습니다.
R10.5.2, R10.6.2, R10.7.1 버전 이전 Ivanti Sentry의 OS 명령 주입 취약점으로 인해 인증되지 않은 원격 사용자가 루트 수준의 원격 코드 실행이 가능해졌습니다.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 100.00 |
| 악용 신호(KEV 등재) | ×1.50 |
| VPI | 100.00 |
VPI 공식 vpi-v1 기준
필수 조치
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.