PT-2025-20921 · Ivanti · Ivanti Endpoint Manager Mobile
Published
2025-05-13
·
Updated
2025-09-20
·
CVE-2025-4428
9.0
High
Base vector | Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
**Name of the Vulnerable Software and Affected Versions:**
Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior
**Description:**
Ivanti Endpoint Manager Mobile (EPMM) contains a remote code execution (RCE) vulnerability in its API component. This flaw is due to improper code generation management. Authenticated attackers can exploit this vulnerability by sending crafted API requests to execute arbitrary code. The vulnerability is actively being exploited by a China-Nexus threat actor (UNC5221) targeting organizations globally, including those in Germany, the UK, the US, Japan, and Korea, for espionage and data theft. Attackers have been observed dumping heap memory from Tomcat Java processes using `jcmd` to search for sensitive information.
**Recommendations:**
Ivanti Endpoint Manager Mobile versions prior to 12.5.0.0 are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Code Injection
Weakness Enumeration
Related Identifiers
Affected Products
References · 190
- https://nvd.nist.gov/vuln/detail/CVE-2025-35036 · Security Note
- https://osv.dev/vulnerability/GHSA-7v6m-28jr-rg84 · Vendor Advisory
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-4428 · Security Note
- https://bdu.fstec.ru/vul/2025-05713 · Security Note
- https://cve.org/CVERecord?id=CVE-2020-5245 · Security Note
- https://cve.org/CVERecord?id=CVE-2025-4428 · Security Note
- https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e67d05ad9eee1ad77e893⭐ 1249 🔗 585 · Note
- https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d7665242dfc7b4d14d78⭐ 1249 🔗 585 · Note
- https://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1b0f47f482218077c5e1⭐ 1249 🔗 585 · Note
- https://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f40e5042709e550ed0d6e⭐ 1249 🔗 585 · Note
- https://github.com/hibernate/hibernate-validator/pull/1138⭐ 1232 🔗 582 · Note
- https://github.com/hibernate/hibernate-validator/compare/6.1.7.Final...6.2.0.Final⭐ 1232 🔗 582 · Note
- https://github.com/hibernate/hibernate-validator⭐ 1228 🔗 580 · Note
- https://t.me/aptreports/18893 · Telegram Post