
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6770 is an OS command injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote authenticated attacker with high privileges to achieve remote code execution. The vulnerability affects EPMM versions before 12.3.0.3, versions 12.4.0.0–12.4.0.2, and versions 12.5.0.0–12.5.0.1. It was published on July 8, 2025, with a patch released on July 11, 2025. The CVSS v3.1 base score is 7.2 (High) (Ivanti Advisory, Red Hat CVE).
The root cause is improper neutralization of special elements used in OS commands (CWE-78), a classic OS command injection flaw. An attacker with high-privilege remote access can craft malicious input that is passed unsanitized to an underlying OS command interpreter, resulting in arbitrary command execution on the EPMM server. Exploitation requires network access and a valid high-privilege account, but no user interaction is needed. The vulnerability was assigned by Ivanti and is tracked alongside a related issue CVE-2025-6771 in the same advisory (Ivanti Advisory, Red Hat CVE).
Successful exploitation allows a privileged remote attacker to execute arbitrary OS commands on the EPMM server, resulting in full compromise of confidentiality, integrity, and availability. An attacker could exfiltrate sensitive mobile device management data (including enrolled device credentials and configurations), modify or delete critical system data, or disrupt EPMM service availability. Given EPMM's role as a mobile device management platform, compromise could facilitate lateral movement to managed endpoints or corporate infrastructure (Ivanti Advisory, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.0101 (roughly 1%), indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Exploitation requires a high-privilege authenticated account, which somewhat limits the attack surface compared to unauthenticated vulnerabilities (Ivanti Advisory).
;, &&, |) followed by the desired command (e.g., a reverse shell or data exfiltration command).;, &&, |, backticks) in parameter values; authentication events for high-privilege accounts at unusual times or from unexpected source IPs./bin/sh, bash, curl, wget, python, nc); new cron jobs or scheduled tasks created under the EPMM service account.Ivanti has released patched versions addressing CVE-2025-6770: upgrade to EPMM 12.3.0.3, 12.4.0.3, or 12.5.0.2 (or later) depending on your current release branch. Organizations should prioritize upgrading to the latest patched version as the primary remediation. As interim measures, restrict access to the EPMM administrative interface to trusted IP ranges, audit and minimize high-privilege accounts, and monitor for suspicious activity. The Canadian Centre for Cyber Security also issued an advisory (AV25-405) recommending prompt patching (Ivanti Advisory, Ivanti Blog, CCCS Advisory).
Ivanti published a security advisory and a July 2025 security update blog post covering CVE-2025-6770 alongside CVE-2025-6771 (Ivanti Blog). The Canadian Centre for Cyber Security issued advisory AV25-405 recommending immediate patching (CCCS Advisory). Security community members on Mastodon (infosec.exchange) noted the disclosure shortly after publication. CyberSecurityNews also covered the vulnerabilities, and Tenable released detection plugins (Nessus plugin 241979) for the flaw (CyberSecurityNews, Tenable).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."