OS Command Injection in Ivanti EPMM Admin Panel
CVE-2025-10243
7.2HIGH
What is CVE-2025-10243?
A vulnerability exists in the admin panel of Ivanti Endpoint Manager Mobile (EPMM) prior to specific versions, where a remote authenticated attacker with administrative privileges can exploit the system. This exploitation allows the attacker to execute arbitrary OS commands, leading to potential system compromise and unauthorized access to sensitive data. It is crucial for organizations utilizing affected versions to apply patches and update software promptly to mitigate such risks.
Affected Version(s)
Endpoint Manager Mobile 12.6.0.2
Endpoint Manager Mobile 12.6.0.2
Endpoint Manager Mobile 12.5.0.4