CVE-2025-13661HIGH 8.0EPSS p62.1%

CVE-2025-13661CVE-2025-13661

Description

Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.

Scoring

CVSS 3.18.0 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS1.13% probability of exploitation · percentile 62.1% · 2026-06-18T12:00:27Z
Published2025-12-09
Last modified2025-12-11

Underlying weaknesses· 1

CWE-22

References

  1. https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024

1

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-13659
CVE
CVE-2025-9713
CVE
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVE
Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
CVE
CVE-2025-9712
CVE
CVE-2025-9872
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.