Ivanti Endpoint Manager Path Traversal Vulnerability Allowing Remote Code Execution

Vulnerability

A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 SU3 SR1 and prior, as well as in the 2022 version through SU8 SR2. This vulnerability allows remote, unauthenticated attackers to execute code on the affected system, although it requires user interaction. The issue arises from improper handling of file paths, which can be exploited to access restricted files or directories, leading to unauthorized code execution.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Remediation

Users of Ivanti Endpoint Manager 2024 SU3 SR1 have a significantly reduced risk due to important security enhancements. For those on versions 2024 SU3 SR1 or prior, it is recommended to move to the latest version of Ivanti EPM 2024. Additionally, EPM administrators can remove the Reporting database user from their configuration to address this vulnerability, but this will disable reporting functionality.

Added: Oct 13, 2025, 9:17 PM
Updated: Oct 13, 2025, 9:17 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
6.0
remediation
8.3
relevance
0.7
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.