CVE-2025-10985
14.10.2025, 15:16
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
| Vendor | Product | Version |
|---|---|---|
| ivanti | endpoint_manager_mobile | 𝑥 < 12.4.0.4 |
| ivanti | endpoint_manager_mobile | 12.5.0.0 ≤ 𝑥 < 12.5.0.4 |
| ivanti | endpoint_manager_mobile | 12.6.0.0 ≤ 𝑥 < 12.6.0.2 |
𝑥
= Vulnerable software versions