PT-2025-20921 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2025-05-13

·

Updated

2025-07-17

·

CVE-2025-4428

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C

**Name of the Vulnerable Software and Affected Versions:**

Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior

**Description:**

Ivanti Endpoint Manager Mobile (EPMM) (formerly MobileIron Core) contains a vulnerability due to improper code generation. This allows a remote attacker to execute arbitrary code. The vulnerability is actively exploited by a China-Nexus threat actor (UNC5221) targeting organizations worldwide, including those in Germany, the UK, the US, Japan, and Korea. Attackers have been observed dumping heap memory from Tomcat Java processes using `jcmd` to search for sensitive information. The exploitation involves a Spring EL Injection vulnerability.

**Recommendations:**

Ivanti Endpoint Manager Mobile versions prior to 12.5.0.0 are affected.

Update to a newer version of Ivanti Endpoint Manager Mobile to address this vulnerability.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-05713
CVE-2025-4428
GHSA-7V6M-28JR-RG84

Affected Products

Ivanti Endpoint Manager Mobile