CVE-2025-9713: Path Traversal
Published Oct 13, 2025
·Updated
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
Affected Software
6 affected components
Ivanti Endpoint Manager<2024
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Ivanti Endpoint Manager=2024-su3
Ivanti Endpoint Manager=2024-su3_security_release_1
Event History
Oct 13, 2025
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 24, 58011
Event
via FIRST·02:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-9713?
CVE-2025-9713 is categorized as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2025-9713?
To fix CVE-2025-9713, upgrade your Ivanti Endpoint Manager to version 2024-su4 or later.
3
What versions of Ivanti Endpoint Manager are affected by CVE-2025-9713?
CVE-2025-9713 affects all versions of Ivanti Endpoint Manager prior to 2024-su4.
4
Can an attacker exploit CVE-2025-9713 without authentication?
Yes, an attacker can exploit CVE-2025-9713 without authentication, making it a high-risk vulnerability.
5
Is user interaction required to exploit CVE-2025-9713?
Yes, user interaction is required for an attacker to successfully exploit CVE-2025-9713.