CVE-2025-4428

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.0.0:*:*:*:*:*:*:*

History

24 Oct 2025, 13:55

Type Values Removed Values Added
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-4428 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-4428 - US Government Resource

21 Oct 2025, 23:17

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-4428 -

21 Oct 2025, 20:20

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-4428', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:21

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-4428 -

21 May 2025, 18:45

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 16:15

Updated : 2025-10-24 13:55


NVD link : CVE-2025-4428

Mitre link : CVE-2025-4428

CVE.ORG link : CVE-2025-4428


JSON object : View

Products Affected

ivanti

  • endpoint_manager_mobile
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')