Junglewise Threat Intelligence

CVE-2025-4428: Ivanti Endpoint Manager Mobile code injection in API component

CVE-2025-4428 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-05-19

Technologies: Ivanti Endpoint Manager Mobile (EPMM), Ivanti Endpoint Manager Mobile, Ivanti MobileIron Core. Vendors: Ivanti.

Executive brief

Ivanti Endpoint Manager Mobile (EPMM) is a platform used by organizations to manage and secure mobile devices. A security vulnerability in its API component allows an attacker with valid login credentials to take full control of the server. This could lead to the theft of sensitive mobile device data, unauthorized access to the corporate network, or a complete shutdown of mobile management services.

Technical details

A code injection vulnerability (CWE-94) exists in the API component of Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior. The flaw stems from an insecure implementation of the Hibernate Validator open-source library (related to CVE-2025-35036). An authenticated attacker can exploit this by sending specially crafted API requests to the server, leading to remote code execution (RCE). While authentication is required, the vulnerability has been observed being exploited in the wild. Administrators should apply the vendor-provided patches or mitigations immediately.

Affected products

  • Ivanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior

Timeline

  • 2025-05-13: disclosed: Initial CVE entry created by Ivanti
  • 2025-05-19: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-05-19: advisory: Vendor advisory published by Ivanti

Related threats