CVE-2025-10986
- EPSS 0.32%
- Veröffentlicht 14.10.2025 14:22:08
- Zuletzt bearbeitet 15.10.2025 18:07:40
Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.
CVE-2025-10985
- EPSS 1.42%
- Veröffentlicht 14.10.2025 14:20:03
- Zuletzt bearbeitet 15.10.2025 18:07:49
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2025-10243
- EPSS 1.42%
- Veröffentlicht 14.10.2025 14:17:55
- Zuletzt bearbeitet 15.10.2025 18:08:01
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2025-10242
- EPSS 1.42%
- Veröffentlicht 14.10.2025 14:14:49
- Zuletzt bearbeitet 15.10.2025 18:07:28
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2025-6771
- EPSS 3.58%
- Veröffentlicht 08.07.2025 15:38:48
- Zuletzt bearbeitet 11.07.2025 17:29:00
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution
CVE-2025-6770
- EPSS 1.83%
- Veröffentlicht 08.07.2025 15:15:33
- Zuletzt bearbeitet 11.07.2025 17:29:21
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution
CVE-2025-4428
- EPSS 56.33%
- Veröffentlicht 13.05.2025 15:46:55
- Zuletzt bearbeitet 24.10.2025 13:55:22
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
CVE-2025-4427
- EPSS 91.45%
- Veröffentlicht 13.05.2025 15:45:35
- Zuletzt bearbeitet 24.10.2025 13:55:27
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
CVE-2024-7612
- EPSS 0.16%
- Veröffentlicht 08.10.2024 17:15:55
- Zuletzt bearbeitet 18.12.2024 18:27:42
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
CVE-2024-36131
- EPSS 1.73%
- Veröffentlicht 07.08.2024 04:17:18
- Zuletzt bearbeitet 21.08.2024 18:35:05
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.