HTTP: Ivanti Endpoint Manager Mobile MobileIron File Service isValid Code Injection

This signature detects attempts to exploit a known vulnerability against Ivanti, Endpoint Manager. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

Affected Products

Ivanti endpoint_manager_mobile

References

CVE: CVE-2025-4428

Short Name
HTTP:CTS:IVANTI-ENDPNT-CODE-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2025-4428 Code Endpoint File Injection Ivanti Manager Mobile MobileIron Service isValid
Release Date
06/10/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3815
False Positive
Unknown
Vendors

Ivanti

Found a potential security threat?