Vulnerability Details CVE-2025-13659
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.5%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2025-13659
-
cpe:2.3:a:ivanti:endpoint_manager:2016.4
-
cpe:2.3:a:ivanti:endpoint_manager:2017.1
-
cpe:2.3:a:ivanti:endpoint_manager:2017.3
-
cpe:2.3:a:ivanti:endpoint_manager:2018.1
-
cpe:2.3:a:ivanti:endpoint_manager:2018.3
-
cpe:2.3:a:ivanti:endpoint_manager:2019.1
-
cpe:2.3:a:ivanti:endpoint_manager:2020.1
-
cpe:2.3:a:ivanti:endpoint_manager:2020.1.1
-
cpe:2.3:a:ivanti:endpoint_manager:2021.1
-
cpe:2.3:a:ivanti:endpoint_manager:2021.1.1
-
cpe:2.3:a:ivanti:endpoint_manager:2022
-
cpe:2.3:a:ivanti:endpoint_manager:2024
-
cpe:2.3:a:ivanti:endpoint_manager:7.9.1.285