Directory Traversal Vulnerability in Ivanti LANDesk Management Gateway
CVE-2025-43716

5.8MEDIUM

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
23 April 2025

Summary

A directory traversal vulnerability has been identified in Ivanti LANDesk Management Gateway versions 4.2-1.9. This flaw allows attackers to manipulate the URI of the /client/index.php endpoint by appending %3F.php, leading to unauthorized access to sensitive web panel endpoints like /client/index.php%3F.php/gsb/firewall.php. This exposure can reveal critical device information and functionalities. It is important to note that this vulnerability affects products that are no longer actively maintained, heightening the risk for organizations still relying on these systems.

Affected Version(s)

LANDesk Management Suite 0 <= 4.2-1.9

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.