Red Hot Cyber, The cybersecurity news

Red Hot Cyber

Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
Crowdtour Promo Banner For Milan V1 320x100 Mobile
UtiliaCS 970x120
12 security bugs discovered in Ivanti Endpoint Manager (EPM). Update now!

12 security bugs discovered in Ivanti Endpoint Manager (EPM). Update now!

Redazione RHC : 14 October 2025 16:29

Ivanti has published 13 vulnerabilities in its Endpoint Manager (EPM) software , including two high-severity flaws that could allow remote code execution and privilege escalation .

Despite the lack of exploitation, CVE-2025-9713 stands out among the vulnerabilities as a high severity path traversal issue with a CVSS score of 8.8, which allows unauthenticated remote attackers to execute arbitrary code if users interact with malicious files.

This is CWE-22, which is exploited due to poor input validation during the configuration import process, which could allow attackers to upload and execute malicious code on the server.

Rounding it all out is CVE-2025-11622, an insecure deserialization vulnerability (CVSS 7.8, CWE-502) that allows local authenticated users to escalate privileges, granting unauthorized access to sensitive system resources.

The remaining 11 vulnerabilities are medium-severity SQL injection flaws (each CVSS 6.5, CWE-89), such as CVE-2025-11623 and CVE-2025-62392 through CVE-2025-62384. The following table lists the overall vulnerabilities detected.

CVE NumberDescriptionCVSS Score (Severity)CVSS VectorCWE
CVE-2025-11622Insecure deserialization in Ivanti Endpoint Manager allows a local authenticated attacker to escalate their privileges.7.8 (High)CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCWE-502
CVE-2025-9713Path traversal in Ivanti Endpoint Manager allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.8.8 (High)CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCWE-22
CVE-2025-11623SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62392SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62390SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62389SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62388SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62387SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62385SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62391SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62383SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62386SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89
CVE-2025-62384SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.6.5 (Medium)CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NCWE-89

Ivanti emphasized that all issues were responsibly reported by researcher 06fe5fd2bc53027c4a3b7e395af0b850e7b8a044 through Trend Micro’s Zero Day Initiative, underscoring the value of coordinated disclosure in strengthening defenses.

At the time of disclosure, Ivanti confirmed that there are no active attacks underway. Therefore, no proof-of-concept exploits or indicators of compromise (IoCs) have been made public.

However, the potential for data exfiltration via SQL injections could facilitate larger campaigns, similar to past incidents targeting management consoles such as those from SolarWinds or Log4j.

Ivanti EPM versions 2024 SU3 SR1 and earlier are affected, while version 2022 has reached end-of-life as of October 2025, leaving users without official support.

For high severity CVEs, fixes are planned for EPM 2024 SU4, which is scheduled for release on November 12, 2025. SQL injections will follow in SU5 in Q1 2026, with a delay due to the complexity of resolving them without disrupting reporting capabilities.

Ivanti emphasized that upgrading to the latest 2024 release already mitigates much of the risk thanks to advanced security controls. Customers with EOL (end-of-life) releases are at greater risk and should migrate promptly to avoid unpatched vulnerabilities.

Immagine del sitoRedazione
The editorial team of Red Hot Cyber consists of a group of individuals and anonymous sources who actively collaborate to provide early information and news on cybersecurity and computing in general.

Lista degli articoli