CVE-2025-4428
13.05.2025, 16:15
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
Vendor | Product | Version |
---|---|---|
ivanti | endpoint_manager_mobile | 𝑥 < 11.12.0.5 |
ivanti | endpoint_manager_mobile | 12.3.0.0 ≤ 𝑥 < 12.3.0.2 |
ivanti | endpoint_manager_mobile | 12.4.0.0 ≤ 𝑥 < 12.4.0.2 |
ivanti | endpoint_manager_mobile | 12.5.0.0 |
𝑥
= Vulnerable software versions
Vulnerability Media Exposure