Full Report
CISA warned U.S. federal agencies to secure their networks against attacks exploiting three critical vulnerabilities affecting Ivanti Endpoint Manager (EPM) appliances. [...]
Analysis Summary
This summary is based *only* on the provided context snippet regarding Ivanti vulnerabilities. The context mentions that CISA tagged critical Ivanti EPM flaws as actively exploited and references previous severe Ivanti vulnerabilities, but it does not explicitly list the CVEs or CVSS scores for the specific EPM flaws being summarized here, nor does it detail the technical breakdown or specific patch versions for those EPM flaws.
# Vulnerability: Actively Exploited Critical Flaws in Ivanti EPM
## CVE Details
- CVE ID: **Not explicitly detailed in the provided text for the EPM flaw.** (The article references CISA adding *five* vulnerabilities to the KEV catalog, but does not list the specific EPM CVEs.)
- CVSS Score: **Unknown/Not specified.**
- CWE: **Unknown/Not specified.**
## Affected Systems
- Products: **Ivanti Endpoint Manager (EPM)** (Implied by the headline; previous context mentions CSA, ICS, IPS, and ZTA gateways were also targeted.)
- Versions: **Not explicitly detailed in the provided text.** (Ivanti has not updated its advisory relating to the EPM flaws mentioned.)
- Configurations: **Unknown/Not specified.**
## Vulnerability Description
The context indicates that critical flaws in Ivanti EPM have been tagged by CISA as being **actively exploited in the wild**. This is occurring in the context of ongoing, widespread exploitation against various Ivanti products, including CSA, utilizing prior zero-days for remote code execution (RCE) leading to malware deployment (e.g., Dryhook and Phasejam by UNC5221).
## Exploitation
- Status: **Actively exploited in the wild** (CISA has added the flaws to its Known Exploited Vulnerabilities (KEV) Catalog).
- Complexity: **Likely Low to Medium**, given the context of mass exploitation seen with other recent Ivanti vulnerabilities.
- Attack Vector: **Likely Network** (typical for remote management software exploitation).
## Impact
- Confidentiality: **High** (Implied by RCE/malware insertion context).
- Integrity: **High** (Implied by RCE/malware insertion context).
- Availability: **High** (Implied by RCE/malware insertion context).
## Remediation
### Patches
- **Patches for the specific critical EPM flaws are not listed.** Ivanti has reportedly not yet updated its security advisory for these specific EPM issues.
- *Note:* Reference is made to past advisories for CSA flaws patched since September.
### Workarounds
- **No specific workarounds for the EPM flaws are provided in this text excerpt.**
- CISA strongly urges all organizations to prioritize timely remediation of KEV Catalog vulnerabilities.
## Detection
- Detection indicators are related to active exploitation targeting Ivanti products generally.
- **Indicators of compromise:** Deployment of malware such as **Dryhook** and **Phasejam** targeting Ivanti systems.
- **Detection methods and tools:** Organizations should monitor for activity related to suspected China-nexus espionage actor **UNC5221**.
## References
- https://www.cisa.gov/news-events/alerts/2025/03/10/cisa-adds-five-known-exploited-vulnerabilities-catalog
- (Context mentions past warnings regarding Ivanti CSA: bepleeingcomputer.com/news/security/cisa-hackers-still-exploiting-older-ivanti-bugs-to-breach-networks/)