Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-10985


OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.


Published

2025-10-14T15:16:01.610

Last Modified

2025-10-15T18:07:49.220

Status

Analyzed

Source

3c1d8aa1-5a33-4ea4-8992-aadd6440af75

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti endpoint_manager_mobile < 12.4.0.4 Yes
Application ivanti endpoint_manager_mobile < 12.5.0.4 Yes
Application ivanti endpoint_manager_mobile < 12.6.0.2 Yes

References