PT-2025-20921 · Ivanti · Ivanti Endpoint Manager Mobile
Published
2025-05-13
·
Updated
2025-07-17
·
CVE-2025-4428
9.0
High
Base vector | Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
**Name of the Vulnerable Software and Affected Versions:**
Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior
**Description:**
Ivanti Endpoint Manager Mobile (EPMM) (formerly MobileIron Core) contains a vulnerability due to improper code generation. This allows a remote attacker to execute arbitrary code. The vulnerability is actively exploited by a China-Nexus threat actor (UNC5221) targeting organizations worldwide, including those in Germany, the UK, the US, Japan, and Korea. Attackers have been observed dumping heap memory from Tomcat Java processes using `jcmd` to search for sensitive information. The exploitation involves a Spring EL Injection vulnerability.
**Recommendations:**
Ivanti Endpoint Manager Mobile versions prior to 12.5.0.0 are affected.
Update to a newer version of Ivanti Endpoint Manager Mobile to address this vulnerability.
Fix
RCE
Code Injection
Weakness Enumeration
Related Identifiers
Affected Products
References · 137
- https://cve.org/CVERecord?id=CVE-2020-5245 · Security Note
- https://osv.dev/vulnerability/GHSA-7v6m-28jr-rg84 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-05713 · Security Note
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-4428 · Security Note
- https://cve.org/CVERecord?id=CVE-2025-4428 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-35036 · Security Note
- https://github.com/hibernate/hibernate-validator⭐ 1228 🔗 580 · Note
- https://github.com/hibernate/hibernate-validator/commit/254858d9dcc4e7cd775d1b0f47f482218077c5e1⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/pull/1138⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/commit/e076293b0ee1bfa97b6e67d05ad9eee1ad77e893⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/commit/05f795bb7cf18856004f40e5042709e550ed0d6e⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/compare/6.1.7.Final...6.2.0.Final⭐ 1227 🔗 579 · Note
- https://github.com/hibernate/hibernate-validator/commit/d2db40b9e7d22c7a0b44d7665242dfc7b4d14d78⭐ 1227 🔗 579 · Note
- https://twitter.com/ScyScan/status/1924662280261918897 · Twitter Post