PT-2025-17626 · Ivanti · Ivanti Landesk Management Gateway
0Xbytehunter
·
Published
2025-04-23
·
Updated
2025-04-23
·
CVE-2025-43716
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ivanti LANDesk Management Gateway versions 4.2-1.9
Description
A directory traversal issue exists, allowing an attacker to bypass access controls and gain unauthorized access to various endpoints within the management web panel by appending
%3F.php to the URI of the /client/index.php endpoint. This could potentially expose sensitive device information.Recommendations
For versions 4.2-1.9, consider restricting access to the
/client/index.php endpoint until a fix is available. As a temporary workaround, avoid using the /client/index.php endpoint with appended parameters like %3F.php to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Landesk Management Gateway