← Back

CVE-2025-4428

nvd nist
Published: May 13, 2025Modified: Oct 24, 2025CISA KEV

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

Affected (4)

1 product
Endpoint Manager Mobile
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Before 11.12.0.5
From 12.3.0.0 to 12.3.0.2
From 12.4.0.0 to 12.4.0.2
Version 12.5.0.0

References (2)

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.