High-Risk Ivanti EPM Vulnerability Opens Door to Admin Session Hijacking
## Overview of Cross-Site Scripting Vulnerability in Ivanti Endpoint Manager
Overview of Cross-Site Scripting Vulnerability in Ivanti Endpoint Manager
A critical stored cross-site scripting (XSS) vulnerability has been identified in Ivanti Endpoint Manager (EPM). This vulnerability, known as CVE-2025-10573, carries a CVSS score of 9.6 and affects all versions below EPM 2024 SU4 SR1. The vulnerability allows unauthenticated attackers to hijack administrator sessions by injecting malicious JavaScript into the management dashboard. This poses a significant threat to enterprise environments managing numerous endpoints.
Ivanti EPM is widely used for endpoint management and vulnerability scanning. The vulnerability arises from an unauthenticated entry point that allows attackers to inject malicious payloads into the administrator dashboard. This issue is due to unsafe handling of device scan data submitted via the '/incomingdata' web API, which lacks proper input validation and output encoding.
Attackers can submit crafted device requests containing XSS payloads to the exposed 'postcgi.exe' CGI binary. The malicious data is automatically processed and stored in the EPM database. When administrators access dashboard pages that display device information, the unencoded XSS payloads execute in their browser context, allowing attackers to gain control over the administrator's authenticated session.
This vulnerability affects versions Ivanti EPM 11.0.6 and below EPM 2024 SU4. The attack does not require valid credentials or prior system access; network connectivity to the EPM web service suffices.
A critical stored cross-site scripting (XSS) vulnerability has been identified in Ivanti Endpoint Manager (EPM).
Ivanti has released version EPM 2024 SU4 SR1 on December 9, 2025, which addresses CVE-2025-10573. Organizations using affected versions should prioritize upgrading to mitigate the vulnerability due to the high privilege level of compromised administrator accounts.
Rapid7 will provide authenticated checks for this vulnerability through Exposure Command, InsightVM, and Nexpose on December 9, 2025, to help organizations identify vulnerable instances.
The vulnerability was discovered by Ryan Emmons, Staff Security Researcher at Rapid7, with close coordination between Rapid7 and the Ivanti security team to ensure timely patching. Ivanti has acknowledged the critical nature of the vulnerability and appreciates Rapid7's collaborative approach to responsible disclosure.
Organizations utilizing Ivanti EPM should treat this vulnerability as critical and apply patches immediately. The attack requires no authentication and targets administrator accounts with full system privileges, making compromise particularly damaging. Implementing network segmentation to restrict access to the EPM web interface and monitoring device scan submissions can provide temporary mitigation while patches are deployed.
Based on reporting by GBHackers.
