VYPR

Management Gateway

by Ivanti

CVEs (2)

  • CVE-2025-43716MedApr 23, 2025
    risk 0.38cvss 5.8epss 0.01

    A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the /client/index.php endpoint, an attacker can bypass access controls and gain unauthorized access to various endpoints such as…

  • CVE-2010-2892Nov 15, 2010
    risk 0.03cvss epss 0.04

    gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.