VYPR

Endpoint Manager

by Ivanti

CVEs (124)

  • CVE-2020-13772MedNov 16, 2020
    risk 0.35cvss 5.3epss 0.02

    In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.

  • CVE-2025-22459MedApr 8, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.

  • CVE-2019-12376MedJun 3, 2019
    risk 0.29cvss 4.5epss 0.01

    Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.

  • CVE-2024-8322MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.01

    Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

Page 7 of 7