Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Why offensive security training benefits the entire security team

INE Security Alerts: Continuous CVE Practices Close the Important Gap Between Vulnerability Alerts and Effective Defense

Owen Tonks-Lewis, Director of Creative Rebel CIC

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » IVANTI Patch EPMM Vulnerability was exploited to remote code execution in limited attacks
Identity

IVANTI Patch EPMM Vulnerability was exploited to remote code execution in limited attacks

userBy userMay 14, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 14, 2025Ravi LakshmananVulnerability/Endpoint Security

Ivanti has released a security update to address two security flaws in Endpoint Manager Mobile (EPMM) software that was taken to an attack to gain remote code execution.

The vulnerabilities in question are listed below –

CVE-2025-4427 (CVSS score: 5.3) – Authentication bypass attackers can access protected resources without proper credentials on IVANTI Endpoint Manager mobile CVE-2025-4428 (CVSS score: 7.2)

Cybersecurity

Defects affect the next version of the product –

11.12.0.4 and previous (fixed to 11.12.0.5) 12.3.0.1 and Prior (fixed to 12.3.0.2) 12.4.0.1 and Front (fixed to 12.4.0.2) 12.5.0.0 and Front (fixed to 12.5.0.1)

Ivanti praised Cert-EU for reporting the issue, but said it “recognizes a very limited number of customers that were exploited during disclosure,” and that the vulnerability was “related to two open source libraries integrated into EPMM.”

However, the company did not disclose the names of the affected libraries. I also don’t know that other software applications that rely on the two libraries may be affected. Additionally, the company is still investigating cases and said it does not have a reliable indicator of compromise related to malicious activities.

“Already filtering access to APIs using either the built-in portal ACLS feature or the external web application firewall will significantly reduce the risk to customers,” Ivanti said.

“This issue only affects ONPREM EPMM products. It is not present in Ivanti neurons in MDM, Ivanti’s cloud-based integrated endpoint management solutions, Ivanti Sentry, or other Ivanti products.”

Cybersecurity

Apart from that, Ivanti has also shipped patches containing authentication bypass defects to the on-premises version of neurons in ITSM (CVE-2025-22462, CVSS score: 9.8). There is no evidence that security flaws are being exploited in the wild.

With zero-days on Ivanti appliances becoming a lightning bolt for threat actors in recent years, it is essential that users move quickly to update their instances to the latest version for optimal protection.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe Trump administration will cut another $450 million with Harvard grants. Donald Trump News
Next Article Fortinet Patches CVE-2025-32756 Zero-Day RCE Fault exploited in Fortivoice System
user
  • Website

Related Posts

Why offensive security training benefits the entire security team

May 14, 2025

Microsoft fixed 78 flaws and exploited five zero-days. CVSS 10 bug affects Azure DevOps servers

May 14, 2025

Fortinet Patches CVE-2025-32756 Zero-Day RCE Fault exploited in Fortivoice System

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Why offensive security training benefits the entire security team

INE Security Alerts: Continuous CVE Practices Close the Important Gap Between Vulnerability Alerts and Effective Defense

Owen Tonks-Lewis, Director of Creative Rebel CIC

New Zealand is set to increase exports with advanced technology

Trending Posts

Did Pakistan shoot down five Indian fighters? What we know | India and Pakistan tension news

May 14, 2025

“I need a banana”: In a spat in Malawi Tanzania, traders are left at Limbo | Trade War News

May 14, 2025

What did India and Pakistan win and lose in military positions? | India and Pakistan tension news

May 14, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

INE Security Alerts: Continuous CVE Practices Close the Important Gap Between Vulnerability Alerts and Effective Defense

Today’s Top Tech Startup Funding News on May 13, 2025

Lead the Digital Revolution: Secure Exclusive TwinH Country Distribution Licenses

Can Your Digital Twin Make You Money? Discover the LEHT Opportunity

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.