PT-2025-41928 · Ivanti · Ivanti Epm
Published
2025-10-14
·
Updated
2025-10-21
·
CVE-2025-10985
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti EPMM versions prior to 12.6.0.2
Ivanti EPMM versions prior to 12.5.0.4
Ivanti EPMM versions prior to 12.4.0.4
Description
A critical operating system command injection flaw exists in the admin panel of Ivanti EPMM. This allows a remote, authenticated attacker with administrative privileges to execute arbitrary operating system commands remotely. The vulnerability allows for remote code execution.
Recommendations
Update Ivanti EPMM to version 12.6.0.2 or later.
Update Ivanti EPMM to version 12.5.0.4 or later.
Update Ivanti EPMM to version 12.4.0.4 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Epm