Impact
Ivanti Endpoint Manager allows an attacker who can authenticate to the system to specify an arbitrary filename for session recording files. This external control of the filename enables the attacker to write files directly into an S3 bucket used for storing session recordings. The result is full write authority over that bucket, allowing the attacker to overwrite, delete, or tamper with recorded data, potentially compromising data integrity, confidentiality, and availability. The vulnerability is a classic example of Improper Restriction on Use of Identifier (CWE‑73) that permits remote control of a file path. Because the flaw requires remote authentication, an attacker must first compromise or use valid credentials to the Endpoint Manager. Once authenticated, the attacker can immediately exploit the file‑name control to modify the storage bucket. The CVSS score of 7.7 denotes high severity; the EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog, but the potential for data loss or compromise remains high.
Affected Systems
Ivanti Endpoint Manager prior to release 2024 SU7 is affected. The core component that processes session recordings configured to use Amazon S3 storage is vulnerable.
Risk and Exploitability
This vulnerability requires the attacker to be authenticated to Endpoint Manager. Once authenticated, the attacker can supply an arbitrary filename during session recording creation, which the system then forwards to the configured S3 bucket. This gives the attacker full write authority over that bucket, allowing overwrites, deletions, or insertion of malicious objects. The CVSS score of 7.7 indicates high severity, while the EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog. Despite these metrics, the potential impact on confidentiality, integrity, and availability of recorded session data is significant.
OpenCVE Enrichment