CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.
Other sources
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4428?
CVE-2025-4428 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2025-4428?
To mitigate CVE-2025-4428, users should upgrade to Ivanti Endpoint Manager Mobile version 12.5.0.1 or later.
What systems are affected by CVE-2025-4428?
CVE-2025-4428 affects Ivanti Endpoint Manager Mobile versions 12.5.0.0 and earlier on unspecified platforms.
Can unprivileged users exploit CVE-2025-4428?
Yes, CVE-2025-4428 allows authenticated attackers, including unprivileged users, to execute arbitrary code.
Is there an exploit available for CVE-2025-4428?
While specific exploits for CVE-2025-4428 are not publicly detailed, the nature of the vulnerability suggests that crafted API requests can be used to exploit it.