CVE Vulnerabilities

CVE-2025-13662

Improper Verification of Cryptographic Signature

Published: Dec 09, 2025 | Modified: Dec 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Endpoint_manager Ivanti * 2024 (excluding)
Endpoint_manager Ivanti 2024 (including) 2024 (including)
Endpoint_manager Ivanti 2024-su1 (including) 2024-su1 (including)
Endpoint_manager Ivanti 2024-su2 (including) 2024-su2 (including)
Endpoint_manager Ivanti 2024-su3 (including) 2024-su3 (including)
Endpoint_manager Ivanti 2024-su3_security_release_1 (including) 2024-su3_security_release_1 (including)
Endpoint_manager Ivanti 2024-su4 (including) 2024-su4 (including)

References