PT-2025-20921 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2025-05-13

·

Updated

2025-10-08

·

CVE-2025-4428

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior
Description A flaw exists in the API component of Ivanti Endpoint Manager Mobile (EPMM) that allows authenticated attackers to execute arbitrary code through crafted API requests. This issue is related to incorrect management of code generation. Reports indicate that this issue is being actively exploited by a China-Nexus threat actor (UNC5221) to target organizations globally, including those in the government, healthcare, and finance sectors, for espionage and data theft. The exploitation involves dumping heap memory from Tomcat Java processes using
jcmd
to search for sensitive information. The vulnerability allows for unauthenticated remote code execution in some instances.
Recommendations For versions prior to 12.5.0.0, apply the latest available updates or patches from Ivanti to address the vulnerability.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-05713
CVE-2025-4428
GHSA-7V6M-28JR-RG84

Affected Products

Ivanti Endpoint Manager Mobile