PT-2025-41928 · Ivanti · Ivanti Epm

Published

2025-10-14

·

Updated

2025-10-21

·

CVE-2025-10985

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti EPMM versions prior to 12.6.0.2 Ivanti EPMM versions prior to 12.5.0.4 Ivanti EPMM versions prior to 12.4.0.4
Description A critical operating system command injection flaw exists in the admin panel of Ivanti EPMM. This allows a remote, authenticated attacker with administrative privileges to execute arbitrary operating system commands remotely. The vulnerability allows for remote code execution.
Recommendations Update Ivanti EPMM to version 12.6.0.2 or later. Update Ivanti EPMM to version 12.5.0.4 or later. Update Ivanti EPMM to version 12.4.0.4 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10985

Affected Products

Ivanti Epm