VDB
GCVE-VVD-NCSC-2025-17
GCVE-VVD-NCSC-2025-17
Advisory PublishedCVSS 9.8/10
Ivanti heeft kwetsbaarheden verholpen in Ivanti Endpoint Manager (EPM) die aanwezig waren in versies vóór de januari 2025 beveiligingsupdates.
Weaknesses (CWE)
CWE-36Absolute Path TraversalCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-502Deserialization of Untrusted DataCWE-908Use of Uninitialized ResourceCWE-787Out-of-bounds WriteCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-434Unrestricted Upload of File with Dangerous TypeCWE-347Improper Verification of Cryptographic Signature
Risk Scores
CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| ivanti | ivanti_endpoint_manager__2024_su1 | — | — |
| ivanti | epm | — | — |
| ivanti | ivanti_endpoint_manager__2022_su6 | — | — |
| ivanti | ivanti_endpoint_manager__2024_security_patch | — | — |
| ivanti | endpoint_manager | — | — |
Aliases
CVE-2024-10811CVE-2024-13166CVE-2024-13169CVE-2024-13159CVE-2024-13167CVE-2024-13160CVE-2024-13165CVE-2024-13158CVE-2024-13168CVE-2024-13162CVE-2024-13170CVE-2024-13171CVE-2024-13161CVE-2024-13164CVE-2024-13172CVE-2024-32848CVE-2024-13163
Transitive aliases
GHSA-c5xq-93hx-p95rGHSA-g5xq-ccc5-74p4CVE-2024-8321GHSA-x4fw-fhfj-vm7cCVE-2024-32845GHSA-cfw8-99m9-5qfmGHSA-6m9g-cw25-j9jcGHSA-qm6j-jqgw-8fcgGHSA-f53w-fw63-qjpwGHSA-35pg-8ph2-rp9cBDU:2024-07250BDU:2025-00409BDU:2025-00411GHSA-pvh3-rvqg-w4qcCVE-2024-32846GHSA-qfx3-m2xp-3pcpCNVD-2024-38821BDU:2024-07157BDU:2025-00398BDU:2024-07251BDU:2024-07734BDU:2024-07155BDU:2025-00397GHSA-v7mj-q2hh-7r72CVE-2024-32842CVE-2024-32843BDU:2024-07274GHSA-w8hf-8rpm-xjp2BDU:2024-07263GHSA-2j3p-vpp9-9f53BDU:2025-00408GHSA-98mp-xvw5-2fchBDU:2025-00404BDU:2025-00396GHSA-qccp-2vxv-82w5BDU:2024-06794BDU:2025-00401CVE-2024-34779CVE-2024-37397GHSA-g7wm-3q7g-g3q2GHSA-rj4v-5f39-crv6VVD-ANCHORE-2024-37397BDU:2025-00402GHSA-6v62-48r8-7wh2BDU:2025-00410GHSA-gg3w-r79x-787fBDU:2025-00405BDU:2024-07154BDU:2025-00406BDU:2024-07268BDU:2024-07158GHSA-rg56-4h6q-rfgqGHSA-vh7p-jh36-p55rGHSA-6358-wjwp-64w4WID-SEC-W-2024-2109CVE-2024-29847BDU:2025-00407CVE-2024-34783CVE-2024-34785CVE-2024-8441BDU:2024-07249GHSA-42p2-q66q-8hx8CNVD-2025-30742BDU:2025-00375GHSA-gwpx-4h2q-gxjqVVD-NCSC-2024-369GHSA-wfg8-6fh4-8fp9BDU:2024-07266GHSA-c45c-r247-q8hcCVE-2024-8320GSD-2024-29847BDU:2024-07248GHSA-h926-5fmr-p532GHSA-r268-64hq-mv45BDU:2024-07273GHSA-5fwx-95cc-hcxvBDU:2025-00399NCSC-2024-0369CVE-2024-32840CVE-2024-8322BDU:2024-07156GHSA-jv5c-8jgx-c489BDU:2025-00403CVE-2024-8191GHSA-pcxj-w6pv-x9c5GHSA-22q6-7m3g-6r77
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.