FAIL › dossier
Endpoint Manager (EPM)
PRODUCT· dossier confidence 0%
Ivanti Endpoint Manager has a critically poor security track record, characterized by a series of high-severity, unauthenticated vulnerabilities including remote code execution and credential leakage. The company's security posture is fundamentally flawed, requiring immediate and rigorous remediation to meet defense-industrial-base compliance standards.
PROFILE
CategoryEndpoint Management SoftwareWhat they doIvanti Endpoint Manager (EPM) is an endpoint management solution that provides IT management, security, and compliance capabilities for organizations.
SECURITY POSTURE
The security posture is severely compromised by a pattern of high-severity, unauthenticated vulnerabilities across multiple years, indicating systemic issues in secure coding, patch management, and threat modeling.
Notable failures
- CVE-2026-1603: Unauthenticated bypass of authentication and credential leakage
- CVE-2024-29824: Unauthenticated SQL injection enabling arbitrary code execution
- CVE-2024-13159: Unauthenticated path traversal enabling sensitive information leakage
Patterns: Repeated unauthenticated high-severity vulnerabilities (RCE, credential leakage, path traversal); Lack of effective patch management or secure development lifecycle (SDL) controls
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-03-09 | CVE-2026-1603 | high | Ivanti Endpoint Manager allows remote unauthenticated attackers to bypass authentication and leak stored credentials via an alternate path. |
| 2024-10-02 | CVE-2024-29824 | high | Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network. |
| 2025-03-10 | CVE-2024-13159 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
| 2025-03-10 | CVE-2024-13160 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
| 2025-03-10 | CVE-2024-13161 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
DOSSIER SOURCES
- Securden, Inc. - Infosecurity Magazine · www.infosecurity-magazine.com
- EPAM Systems, Inc. - Investors · investors.epam.com
- Overview - Admin-User-ENU - Ivanti · docs.ivanti.com
- Evommune (EVMN) Company Headquarters · www.financecharts.com
- EPAM Systems (EPAM) Company Profile & Description · stockanalysis.com
Open questions: Ivanti's corporate headquarters location · Ivanti's founding year · Ivanti's current ownership structure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:52:50.301244+00:00