Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Jul 9, 2025
OS command injection in Ivanti Endpoint Manager
CVE-2025-6771
Description
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution
Affected products
2- Range: <=12.5.0.2,<=12.4.0.3,<=12.3.0.3
- Ivanti/Endpoint Manager Mobilev5Range: 12.5.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.