VendorsIvantiendpoint_manager2024
Vulnerabilities

Ivanti Endpoint Manager 2024

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

84CVEs
CVE-2025-22465
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.
Published 2025-04-08 · Analyzed
6.1EPSS 0.006
CVE-2025-22464
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.
Published 2025-04-08 · Analyzed
6.1EPSS 0.002
CVE-2024-8320
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
Published 2024-09-10 · Analyzed
5.3EPSS 0.012
CVE-2025-22459
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.
Published 2025-04-08 · Analyzed
4.8EPSS 0.003
← Prev3 / 3