Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4428


Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.


Published

2025-05-13T16:15:32.463

Last Modified

2025-05-21T18:45:24.800

Status

Analyzed

Source

3c1d8aa1-5a33-4ea4-8992-aadd6440af75

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti endpoint_manager_mobile < 11.12.0.5 Yes
Application ivanti endpoint_manager_mobile < 12.3.0.2 Yes
Application ivanti endpoint_manager_mobile < 12.4.0.2 Yes
Application ivanti endpoint_manager_mobile 12.5.0.0 Yes

References