CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-10573

CVSS 9.6v3.1pub. 2025-12-09upd. 2025-12-11

Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.

🤖 AI Analysis
How it works

An attacker without any authentication can inject malicious JavaScript code, which is permanently stored (stored) in the Ivanti Endpoint Manager application. The script is then automatically executed in the browser of a logged-in administrator when the infected content is displayed. The attack requires user (administrator) interaction, such as visiting a specific page or view in the management panel. Because the payload operates in the context of a privileged session, the attacker can perform operations with administrator privileges.

Impact

An attacker can execute arbitrary JavaScript code in the context of an administrator's session, which in practice can lead to account takeover, theft of authentication credentials, modification of endpoint management environment configuration, or further lateral movement in the network.

Mitigation & patch

Ivanti Endpoint Manager should be updated to version 2024 SU4 SR1 or later. Details are available in the vendor's official security bulletin: https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024

Who is affected

Ivanti Endpoint Manager in versions prior to 2024 SU4 SR1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Ivanti Endpoint Manager

    APP
    Ivanti
    2024< 2024
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSSAuth Bypass
CWE
References

Related vulnerabilities

CVE-2024-13161CRITICAL9.8⚠ KEVPL ✓same product

Absolute Path Traversal w Ivanti EPM — wyciek wrażliwych danych bez uwierzytelnienia

CVE-2024-13160CRITICAL9.8⚠ KEVPL ✓same product

Absolute Path Traversal w Ivanti EPM — wyciek wrażliwych danych bez uwierzytelnienia

CVE-2024-13159CRITICAL9.8⚠ KEVPL ✓same product

Absolute Path Traversal w Ivanti EPM — wyciek danych bez uwierzytelnienia

CVE-2024-10811CRITICAL9.8PL ✓same product

Absolute Path Traversal w Ivanti Endpoint Manager — wyciek danych bez uwierzytelnienia

CVE-2024-50330CRITICAL9.8PL ✓same product

SQL Injection w Ivanti Endpoint Manager umożliwiający RCE bez uwierzytelnienia