9.6
CVE-2025-22466
- EPSS 1.07%
- Veröffentlicht 08.04.2025 14:27:55
- Zuletzt bearbeitet 16.05.2025 14:00:29
- Erkennungen
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ivanti ≫ Endpoint Manager Version < 2022
Ivanti ≫ Endpoint Manager Version 2022 Update -
Ivanti ≫ Endpoint Manager Version 2022 Update su1
Ivanti ≫ Endpoint Manager Version 2022 Update su2
Ivanti ≫ Endpoint Manager Version 2022 Update su3
Ivanti ≫ Endpoint Manager Version 2022 Update su4
Ivanti ≫ Endpoint Manager Version 2022 Update su5
Ivanti ≫ Endpoint Manager Version 2022 Update su6
Ivanti ≫ Endpoint Manager Version 2024 Update -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.07% | 0.608 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
| 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 | 8.2 | 2.8 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://forums.ivanti.com/s/article/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6