Ivanti Endpoint Manager Mobile
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*
- <= 12.5.0.0
- <= 12.6.0.0
- <= 12.7.0.0
- <= 12.5.1.0
- <= 12.6.1.0
This vulnerability is being actively exploited in the wild.
A code injection vulnerability has been identified in Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior, 12.6.0.0 and prior, and 12.7.0.0 and prior. This vulnerability allows attackers to execute code remotely without authentication.
Exploitation of this vulnerability allows for unauthenticated remote code execution on the affected system.
Users should upgrade to Ivanti Endpoint Manager Mobile version 12.8.0.0 or apply the specific RPM patch available for their current version. Instructions for applying the patch are provided in the Ivanti security advisory.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.