Affected Systems
Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.
Exploitation Status
Active exploitation confirmed. Attackers targeting Internet-exposed Ivanti Sentry instances to achieve remote code execution with root privileges.
Business Impact
Maximum severity RCE vulnerability grants attackers root-level access to Ivanti Sentry gateways, enabling full system compromise, lateral movement into internal networks, data exfiltration, and potential supply chain attacks against mobile device management infrastructure. Organizations with Internet-exposed Sentry instances face immediate risk of breach.
Urgency
🔴 Immediate
Recommended Actions
- Immediately identify all Internet-exposed Ivanti Sentry instances and apply the latest security patch released by Ivanti
- If patching cannot be completed within hours, isolate Ivanti Sentry systems from the Internet or shut down until patched
- Review Sentry system logs and network traffic for indicators of compromise, focusing on unusual authentication attempts, unexpected processes, or outbound connections
- Conduct forensic analysis on any Sentry instance that was Internet-exposed prior to patching to detect potential compromise
- Implement network segmentation to limit Sentry gateway access and monitor all traffic to/from these systems with enhanced logging
