PT-2025-41813 · Ivanti · Ivanti Endpoint Manager

Published

2025-10-07

·

Updated

2025-11-12

·

CVE-2025-9713

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager (affected versions not specified)
Description A path traversal issue exists in Ivanti Endpoint Manager, potentially enabling a remote, unauthenticated attacker to execute code on a system. User interaction is necessary for exploitation, requiring a user to perform specific actions. The vulnerability stems from insufficient validation of file paths during certain operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-12911
CVE-2025-9713
ZDI-25-935

Affected Products

Ivanti Endpoint Manager