VYPR

Endpoint Manager Mobile

by Ivanti

CVEs (98)

  • CVE-2023-39337CriNov 15, 2023
    risk 0.59cvss 9.1epss 0.02

    A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability…

  • CVE-2026-5787HigMay 7, 2026
    risk 0.58cvss 8.9epss 0.01

    An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

  • CVE-2026-5786HigMay 7, 2026
    risk 0.58cvss 8.8epss 0.06

    An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

  • CVE-2025-9713HigOct 13, 2025
    risk 0.58cvss 8.8epss 0.15

    Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2025-9872HigSep 9, 2025
    risk 0.58cvss 8.8epss 0.14

    Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2023-39336HigJan 9, 2024
    risk 0.58cvss 8.8epss 0.10

    An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this…

  • CVE-2025-13659HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.02

    Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.

  • CVE-2025-4427MedKEVMay 13, 2025
    risk 0.57cvss 5.3epss 1.00

    An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

  • CVE-2024-50329HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2024-7612HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

  • CVE-2024-36131HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.02

    An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.

  • CVE-2025-6996HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

  • CVE-2025-6995HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

  • CVE-2025-22466HigApr 8, 2025
    risk 0.53cvss 8.2epss 0.01

    Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

  • CVE-2024-13171HigJan 14, 2025
    risk 0.52cvss 7.8epss 0.18

    Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

  • CVE-2024-13162HigJan 14, 2025
    risk 0.52cvss 7.2epss 0.64

    SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.

  • CVE-2024-8191HigSep 10, 2024
    risk 0.52cvss 7.8epss 0.20

    SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2025-13662HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.

  • CVE-2025-11622HigOct 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.

  • CVE-2025-22458HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

Page 2 of 5