Ivanti warns customers of new EPM flaw enabling remote code execution
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-13159 | Unauthenticated Absolute Path Traversal Info Leak in Ivanti Endpoint Manager (EPM) CVE-2024-13159 is an absolute path traversal vulnerability (CWE-36) in Ivanti Endpoint Manager (EPM) that allows a remote, unauthenticated attacker to leak sensitive information from the server. It is triggered when the EPM server processes attacker-supplied requests containing absolute file-system paths without properly constraining them, letting the attacker retrieve files outside the intended directory. A successful attack discloses arbitrary file contents, which could include configuration or credential material useful for further compromise; the available data describes information disclosure only, not code execution. Any organization running an Ivanti EPM management server, particularly one reachable by untrusted networks, is affected, though the source data does not specify affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-10, indicating confirmed in-the-wild exploitation, and EPSS assigns it a 100% probability of exploitation within 30 days; no public proof-of-concept is known. Do: Apply the fixed updates identified in Ivanti's security advisory (specific patched versions are not included in the available data), and follow CISA KEV required action: apply vendor mitigations, comply with BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Until patched, restrict network access to the EPM management server to trusted networks and review HTTP/server logs for requests referencing absolute file paths that could indicate exploitation. | 7.5 | 100% | KEV PoC |
| largeon the order of tens of thousands of EPM management-server deployments (unknown share remotely exploitable) | |
| CVE-2025-10573 | Stored Cross-Site Scripting in Ivanti Endpoint Manager Exposes Admin Sessions CVE-2025-10573 is a stored cross-site scripting (CWE-79) flaw in Ivanti Endpoint Manager versions prior to 2024 SU4 SR1. A remote, unauthenticated attacker can plant malicious script content in the product, and when an administrator interacts with the affected view (user interaction is required), arbitrary JavaScript executes in the context of the administrator's browser session. An attacker who succeeds can act as an EPM administrator, potentially viewing or modifying administrative data, which the scope-changed CVSS 3.1 score of 6.1 reflects via low confidentiality and integrity impact. Organizations running Ivanti EPM on-premises, typically to manage large fleets of corporate endpoints, are affected. As of now there is no known public proof-of-concept and the flaw is not in CISA KEV, but EPSS assigns a 33.5% probability of exploitation within 30 days (98th percentile), indicating elevated risk. Do: Upgrade Ivanti Endpoint Manager to 2024 SU4 SR1 or later as soon as possible, and apply the latest Ivanti patch rollups, since related advisories indicate Ivanti shipped fixes for multiple EPM issues in the same cycle. Until patched, restrict network access to the EPM core server and administrative console, and have administrators avoid engaging with unexpected or untrusted content in the console. After patching, review EPM administrator accounts and recent session activity for signs of unauthorized administrative actions. | 6.1 | 33% |
| largetens of thousands of EPM core deployments worldwide (widely deployed enterprise endpoint-management platform) |
Full article391 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 09, 2025

Ivanti warns users to address a newly disclosed Endpoint Manager vulnerability that could let attackers execute code remotely.
Software firm Ivanti addressed a newly disclosed vulnerability, tracked as CVE-2025-10573 (CVSS score 9.6), in its Endpoint Manager (EPM) solution.
The vulnerability is a Stored XSS that could allow a remote unauthenticated attacker to execute arbitrary
“Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.” reads the advisory.
The flaw impacts Ivanti Endpoint Manager prior to version 2024 SU4 SR1.
Ivanti EPM is a widely used solution for remote administration and vulnerability management. It lets authenticated admins control and install software on endpoints, making it an attractive target for attackers.
Rapid7 researchers warn that an unauthenticated attacker can register fake endpoints with Ivanti EPM and inject malicious JavaScript into the admin dashboard. When an administrator views the poisoned interface, the script executes and lets the attacker hijack the admin session. Because this flaw requires no authentication, organizations are urged to patch immediately.
“An attacker with unauthenticated access to the primary EPM web service can join fake managed endpoints to the EPM server in order to poison the administrator web dashboard with malicious JavaScript.” reads the report published by Rapid7. “When an Ivanti EPM administrator views one of the poisoned dashboard interfaces during normal usage, that passive user interaction will trigger client-side JavaScript execution, resulting in the attacker gaining control of the administrator’s session.”
Rapid7 researchers noted that the unauthenticated incomingdata API accepts device scan data and writes it to a processing directory, where it’s later parsed and displayed on the admin dashboard. Attackers can submit scans containing malicious JavaScript, which is then embedded into the interface. When an admin views affected pages, the script executes and lets the attacker hijack the session. This occurs because the CGI handler (postcgi.exe) processes key=value scan files without sanitizing input.
Ivanti is not aware of attacks in the wild exploiting this vulnerability.
In March, the U.S. cybersecurity agency CISA added multiple EPM vulnerabilities (CVE-2024-13159, CVE-2024-13160, CVE-2024-13161) to its Known Exploited Vulnerabilities (KEV) catalog
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Ivanti EPM)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185508/hacking/ivanti-warns-customers-of-new-epm-flaw-enabling-remote-code-execution.html