CVE-2025-4428

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ivantiCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
ivantiendpoint_manager_mobile
𝑥
< 11.12.0.5
ivantiendpoint_manager_mobile
12.3.0.0 ≤
𝑥
< 12.3.0.2
ivantiendpoint_manager_mobile
12.4.0.0 ≤
𝑥
< 12.4.0.2
ivantiendpoint_manager_mobile
12.5.0.0
𝑥
= Vulnerable software versions