Directory Traversal Vulnerability in Ivanti LANDesk Management Gateway
CVE-2025-43716
What is CVE-2025-43716?
A directory traversal vulnerability has been identified in Ivanti LANDesk Management Gateway versions 4.2-1.9. This flaw allows attackers to manipulate the URI of the /client/index.php endpoint by appending %3F.php, leading to unauthorized access to sensitive web panel endpoints like /client/index.php%3F.php/gsb/firewall.php. This exposure can reveal critical device information and functionalities. It is important to note that this vulnerability affects products that are no longer actively maintained, heightening the risk for organizations still relying on these systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LANDesk Management Suite 0 <= 4.2-1.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved