PT-2025-20921 · Ivanti · Ivanti Endpoint Manager Mobile
Published
2025-05-13
·
Updated
2025-10-08
·
CVE-2025-4428
CVSS v2.0
9.0
9.0
High
| Base vector | Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior
Description
A flaw exists in the API component of Ivanti Endpoint Manager Mobile (EPMM) that allows authenticated attackers to execute arbitrary code through crafted API requests. This issue is related to incorrect management of code generation. Reports indicate that this issue is being actively exploited by a China-Nexus threat actor (UNC5221) to target organizations globally, including those in the government, healthcare, and finance sectors, for espionage and data theft. The exploitation involves dumping heap memory from Tomcat Java processes using
jcmd to search for sensitive information. The vulnerability allows for unauthenticated remote code execution in some instances.Recommendations
For versions prior to 12.5.0.0, apply the latest available updates or patches from Ivanti to address the vulnerability.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-05713
CVE-2025-4428
GHSA-7V6M-28JR-RG84
Affected Products
Ivanti Endpoint Manager Mobile
References · 199
- https://cve.org/CVERecord?id=CVE-2020-5245 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-35036 · Security Note
- https://osv.dev/vulnerability/GHSA-7v6m-28jr-rg84 · Vendor Advisory
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-4428 · Security Note
- https://bdu.fstec.ru/vul/2025-05713 · Security Note
- https://cve.org/CVERecord?id=CVE-2025-4428 · Security Note
- https://github.com/hibernate/hibernate-validator/compare/6.1.7.Final...6.2.0.Final⭐ 1252 🔗 586 · Note
- https://github.com/hibernate/hibernate-validator/pull/1138⭐ 1252 🔗 586 · Note
- https://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f40e5042709e550ed0d6e⭐ 1249 🔗 585 · Note
- https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d7665242dfc7b4d14d78⭐ 1249 🔗 585 · Note
- https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e67d05ad9eee1ad77e893⭐ 1249 🔗 585 · Note
- https://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1b0f47f482218077c5e1⭐ 1249 🔗 585 · Note
- https://github.com/hibernate/hibernate-validator⭐ 1228 🔗 580 · Note
- https://twitter.com/amirahcolorado/status/1928234372777337271 · Twitter Post