PT-2025-41927 · Ivanti · Ivanti Epm

Published

2025-10-14

·

Updated

2025-10-15

·

CVE-2025-10243

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti EPMM versions prior to 12.6.0.2 Ivanti EPMM versions prior to 12.5.0.4 Ivanti EPMM versions prior to 12.4.0.4
Description A flaw exists in the admin panel of Ivanti EPMM that allows a remote authenticated attacker with admin privileges to execute arbitrary OS commands, potentially leading to remote code execution. The vulnerability is present in versions prior to 12.6.0.2, 12.5.0.4, and 12.4.0.4.
Recommendations Update Ivanti EPMM to version 12.6.0.2 or later. Update Ivanti EPMM to version 12.5.0.4 or later. Update Ivanti EPMM to version 12.4.0.4 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10243

Affected Products

Ivanti Epm