PT-2025-41926 · Ivanti · Ivanti Epm

Published

2025-10-14

·

Updated

2025-10-15

·

CVE-2025-10242

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti EPMM versions prior to 12.6.0.2 Ivanti EPMM versions prior to 12.5.0.4 Ivanti EPMM versions prior to 12.4.0.4
Description A flaw exists in the admin panel of the software that allows for OS command injection. A remote, authenticated attacker with administrative privileges can achieve remote code execution. The attacker can run arbitrary commands as root.
Recommendations Update Ivanti EPMM to version 12.6.0.2 or later. Update Ivanti EPMM to version 12.5.0.4 or later. Update Ivanti EPMM to version 12.4.0.4 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10242

Affected Products

Ivanti Epm