Ivanti Endpoint Manager Mobile(Ivanti EPMM)是美国Ivanti公司的一个移动管理软件引擎。 Ivanti Endpoint Manager Mobile 12.5.0.0及之前版本存在安全漏洞,该漏洞源于API组件身份验证绕过,可能导致访问受保护资源。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Ivanti | Endpoint Manager Mobile | 12.5.0.1 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | An authentication bypass in Ivanti Endpoint Manager Mobile allowing attackers to access protected resources without proper credentials. This leads to unauthenticated Remote Code Execution via unsafe userinput in one of the bean validators which is sink for Server-Side Template Injection. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4427.yaml | POC详情 |
| 2 | None | https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428 | POC详情 |
| 3 | Detection for CVE-2025-4427 and CVE-2025-4428 | https://github.com/rxerium/CVE-2025-4427-CVE-2025-4428 | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2025-22462 | 9.8 CRITICAL | Ivanti Neurons for ITSM 安全漏洞 |
| CVE-2025-22460 | 7.8 HIGH | Ivanti Cloud Services Application 安全漏洞 |
| CVE-2025-4428 | 7.2 HIGH | Ivanti Endpoint Manager Mobile 代码注入漏洞 |
暂无评论