← Back to CVE List
CVE-2025-4428NVD
Vulnerability Summary
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
CVSS v3.1 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Ivanti Endpoint Manager Mobile < 11.12.0.5
- Ivanti Endpoint Manager Mobile >= 12.3.0.0 and < 12.3.0.2
- Ivanti Endpoint Manager Mobile >= 12.4.0.0 and < 12.4.0.2
- Ivanti Endpoint Manager Mobile
- Ivanti Endpoint Manager Mobile 11.12.0.5
- Ivanti Endpoint Manager Mobile 12.3.0.2
- Ivanti Endpoint Manager Mobile 12.4.0.2