Ivanti has identified two OS command injection flaws, tracked as CVE-2025-6770 and CVE-2025-6771, in versions of Ivanti Endpoint Manager Mobile prior to 12.5.0.2. Both vulnerabilities carry a CVSS score of 7.2 (High), indicating significant risk. Ivanti disclosed two high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) product, which could allow remote attackers to execute code on affected systems. Addressing concerns about exploitation, Ivanti confirmed that no customers have been compromised by these vulnerabilities prior to public disclosure. The vulnerabilities impact multiple versions of Ivanti Endpoint Manager Mobile. Ivanti customers should act swiftly to ensure their systems are secure against these critical vulnerabilities. At the time of disclosure, Ivanti has stated that it is not aware of any active exploitation of these vulnerabilities. Ivanti extended gratitude to Piotr Bazydlo (@chudyPB) of watchTowr for responsibly reporting CVE-2025-6771 and collaborating to protect customers.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 08 Jul 2025 15:55:15 +0000