Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Act 2 of Drive Capital – How Columbus Ventures Success After Split

Don’t ask the blue ski toll ruble, it’s a toll for you

Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » IVANTI Patch EPMM Vulnerability was exploited to remote code execution in limited attacks
Identity

IVANTI Patch EPMM Vulnerability was exploited to remote code execution in limited attacks

userBy userMay 14, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 14, 2025Ravi LakshmananVulnerability/Endpoint Security

Ivanti has released a security update to address two security flaws in Endpoint Manager Mobile (EPMM) software that was taken to an attack to gain remote code execution.

The vulnerabilities in question are listed below –

CVE-2025-4427 (CVSS score: 5.3) – Authentication bypass attackers can access protected resources without proper credentials on IVANTI Endpoint Manager mobile CVE-2025-4428 (CVSS score: 7.2)

Cybersecurity

Defects affect the next version of the product –

11.12.0.4 and previous (fixed to 11.12.0.5) 12.3.0.1 and Prior (fixed to 12.3.0.2) 12.4.0.1 and Front (fixed to 12.4.0.2) 12.5.0.0 and Front (fixed to 12.5.0.1)

Ivanti praised Cert-EU for reporting the issue, but said it “recognizes a very limited number of customers that were exploited during disclosure,” and that the vulnerability was “related to two open source libraries integrated into EPMM.”

However, the company did not disclose the names of the affected libraries. I also don’t know that other software applications that rely on the two libraries may be affected. Additionally, the company is still investigating cases and said it does not have a reliable indicator of compromise related to malicious activities.

“Already filtering access to APIs using either the built-in portal ACLS feature or the external web application firewall will significantly reduce the risk to customers,” Ivanti said.

“This issue only affects ONPREM EPMM products. It is not present in Ivanti neurons in MDM, Ivanti’s cloud-based integrated endpoint management solutions, Ivanti Sentry, or other Ivanti products.”

Cybersecurity

Apart from that, Ivanti has also shipped patches containing authentication bypass defects to the on-premises version of neurons in ITSM (CVE-2025-22462, CVSS score: 9.8). There is no evidence that security flaws are being exploited in the wild.

With zero-days on Ivanti appliances becoming a lightning bolt for threat actors in recent years, it is essential that users move quickly to update their instances to the latest version for optimal protection.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe Trump administration will cut another $450 million with Harvard grants. Donald Trump News
Next Article Fortinet Patches CVE-2025-32756 Zero-Day RCE Fault exploited in Fortivoice System
user
  • Website

Related Posts

Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

July 5, 2025

The exposed JDWP interface leads to crypto mining, and Hpingbot targets DDO’s SSH

July 5, 2025

TwinH: A New Frontier in the Pursuit of Immortality?

July 4, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Act 2 of Drive Capital – How Columbus Ventures Success After Split

Don’t ask the blue ski toll ruble, it’s a toll for you

Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

The exposed JDWP interface leads to crypto mining, and Hpingbot targets DDO’s SSH

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.