PT-2025-41929 · Ivanti · Ivanti Epm
Published
2025-10-14
·
Updated
2025-10-15
·
CVE-2025-10986
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Ivanti EPMM versions prior to 12.6.0.2
Ivanti EPMM versions prior to 12.5.0.4
Ivanti EPMM versions prior to 12.4.0.4
Description
A path traversal issue exists in the admin panel of Ivanti EPMM. A remote, authenticated attacker with administrative privileges can write data to unintended locations on disk. The issue involves an admin-to-root path traversal, allowing arbitrary data to be written.
Recommendations
Update Ivanti EPMM to version 12.6.0.2 or later.
Update Ivanti EPMM to version 12.5.0.4 or later.
Update Ivanti EPMM to version 12.4.0.4 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Epm