ZeroHour

CVE-2025-10573

large

Stored Cross-Site Scripting in Ivanti Endpoint Manager Exposes Admin Sessions

CVSS 3.1
6.1 medium
EPSS
33%p98
Published
()
Modified
AI analysis

CVE-2025-10573 is a stored cross-site scripting (CWE-79) flaw in Ivanti Endpoint Manager versions prior to 2024 SU4 SR1. A remote, unauthenticated attacker can plant malicious script content in the product, and when an administrator interacts with the affected view (user interaction is required), arbitrary JavaScript executes in the context of the administrator's browser session. An attacker who succeeds can act as an EPM administrator, potentially viewing or modifying administrative data, which the scope-changed CVSS 3.1 score of 6.1 reflects via low confidentiality and integrity impact. Organizations running Ivanti EPM on-premises, typically to manage large fleets of corporate endpoints, are affected. As of now there is no known public proof-of-concept and the flaw is not in CISA KEV, but EPSS assigns a 33.5% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

What to do: Upgrade Ivanti Endpoint Manager to 2024 SU4 SR1 or later as soon as possible, and apply the latest Ivanti patch rollups, since related advisories indicate Ivanti shipped fixes for multiple EPM issues in the same cycle. Until patched, restrict network access to the EPM core server and administrative console, and have administrators avoid engaging with unexpected or untrusted content in the console. After patching, review EPM administrator accounts and recent session activity for signs of unauthorized administrative actions.

Affected
Ivanti Endpoint Managerprior to 2024 SU4 SR1
Estimated exposure
largetens of thousands of EPM core deployments worldwide (widely deployed enterprise endpoint-management platform) — Ivanti EPM is a long-standing on-premises endpoint-management suite used by mid-size and large organizations to manage endpoint fleets, and while only a subset of management cores and consoles are internet-exposed in public scans, the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news