PT-2025-20920 · Ivanti · Ivanti Endpoint Manager Mobile
Published
2025-05-13
·
Updated
2025-07-17
·
CVE-2025-4427
7.5
High
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
**Name of the Vulnerable Software and Affected Versions:**
Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and earlier
**Description:**
An authentication bypass vulnerability exists in the API component of Ivanti Endpoint Manager Mobile (EPMM). This flaw allows attackers to access protected resources without proper credentials via the API. Exploitation of this vulnerability has been observed in real-world attacks by the China-linked UNC5221 threat actor, targeting organizations in the defense, healthcare, and finance sectors. These attacks involve the deployment of malware such as KrustyLoader and Sliver. The vulnerability enables unauthenticated Remote Code Execution (RCE). Over 1,400 exposed instances have been identified in the US and Germany.
**Recommendations:**
Ivanti Endpoint Manager Mobile versions prior to 12.5.0.0 should be updated to a fixed version. As a temporary workaround, consider filtering API access to minimize the risk of exploitation.
Fix
RCE
Authentication Bypass Using an Alternate Path or Channel
Code Injection
Related Identifiers
Affected Products
References · 152
- https://nvd.nist.gov/vuln/detail/CVE-2025-35036 · Security Note
- https://osv.dev/vulnerability/GHSA-7v6m-28jr-rg84 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-05712 · Security Note
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-4427 · Security Note
- https://cve.org/CVERecord?id=CVE-2020-5245 · Security Note
- https://cve.org/CVERecord?id=CVE-2025-4428 · Security Note
- https://github.com/hibernate/hibernate-validator⭐ 1228 🔗 580 · Note
- https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d7665242dfc7b4d14d78⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f40e5042709e550ed0d6e⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e67d05ad9eee1ad77e893⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/compare/6.1.7.Final...6.2.0.Final⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/pull/1138⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1b0f47f482218077c5e1⭐ 1227 🔗 579 · Note
- https://twitter.com/dCypherIO/status/1925280436856463733 · Twitter Post