CVE-2025-9713: Path Traversal
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Managerto a version that resolves this vulnerability.Fixed in 2024 SU4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9713?
CVE-2025-9713 is categorized as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2025-9713?
To fix CVE-2025-9713, upgrade your Ivanti Endpoint Manager to version 2024-su4 or later.
What versions of Ivanti Endpoint Manager are affected by CVE-2025-9713?
CVE-2025-9713 affects all versions of Ivanti Endpoint Manager prior to 2024-su4.
Can an attacker exploit CVE-2025-9713 without authentication?
Yes, an attacker can exploit CVE-2025-9713 without authentication, making it a high-risk vulnerability.
Is user interaction required to exploit CVE-2025-9713?
Yes, user interaction is required for an attacker to successfully exploit CVE-2025-9713.