CVE-2025-6771: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Ivanti Endpoint Manager Mobile
Severity: highType: vulnerabilityCVE-2025-6771
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution
CVE-2025-6771: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Ivanti Endpoint Manager Mobile
High
Published: Tue Jul 08 2025 (07/08/2025, 15:38:48 UTC)
Source: CVE Database V5
Vendor/Project: Ivanti
Product: Endpoint Manager Mobile
Description
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- ivanti
- Date Reserved
- 2025-06-27T09:27:02.021Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 686d3f3d6f40f0eb72f82b12
Added to database: 7/8/2025, 3:54:37 PM
Last updated: 7/8/2025, 3:54:37 PM
Views: 1
Related Threats
CVE-2025-43019: CWE-269 Improper Privilege Management in HP Inc. HP Support Assistant
MediumVulnerabilityTue Jul 08 2025
CVE-2025-7184: SQL Injection in code-projects Library System
MediumVulnerabilityTue Jul 08 2025
CVE-2025-5464: CWE-532 Insertion of Sensitive Information into Log File in Ivanti Connect Secure
MediumVulnerabilityTue Jul 08 2025
CVE-2025-0293: CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') in Ivanti Connect Secure
MediumVulnerabilityTue Jul 08 2025
CVE-2025-0292: CWE-918 Server-Side Request Forgery (SSRF) in Ivanti Connect Secure
MediumVulnerabilityTue Jul 08 2025
Actions
Please log in to the Console to use AI analysis features.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.