CVE-2025-1281
8.8Ivanti · Endpoint Manager Mobile (EPMM)
A pre-authentication Remote Code Execution vulnerability in Ivanti EPMM allows unauthenticated attackers to execute arbitrary code via malicious HTTP requests handled by legacy bash scripts.
Executive summary
Ivanti EPMM is affected by a critical pre-authentication remote code execution vulnerability that is currently being exploited in the wild.
Vulnerability
The vulnerability originates from improper handling of HTTP requests within legacy bash scripts, enabling unauthenticated attackers to execute arbitrary code remotely. This flaw grants an attacker the ability to gain full control over the EPMM appliance and potentially impact all managed mobile devices.
Business impact
With a CVSS score of 8.8 (High), this vulnerability poses an extreme risk to organizational security. Because the vulnerability is unauthenticated and allows for remote code execution, it provides a direct path for attackers to compromise the entire mobile device management infrastructure, leading to total loss of confidentiality, integrity, and availability.
Remediation
Immediate Action: Upgrade to Ivanti Endpoint Manager Mobile versions 12.6.1.1, 12.7.0.1, or 12.8.0.1 immediately.
Proactive Monitoring: Inspect system logs for unusual outbound connections or unauthorized process executions originating from the EPMM appliance.
Compensating Controls: Restrict management interface access to trusted internal networks or VPNs to limit the exposure of the vulnerable endpoint to the public internet.
Exploitation status
Public Exploit Available: Yes (Confirmed by Ivanti and CISA KEV)
Analyst recommendation
This vulnerability represents a critical threat to enterprise mobile security. Administrators must apply the provided patches immediately to prevent full system compromise and potential lateral movement within the network.
More Ivanti CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief high section
Sources
Originally found and disclosed by Tonn, per the CVE Program record.