BRIEFING NOTE: CVE-2025-65115 OVERVIEW CVE-2025-65115 is a remote code execution vulnerability affecting multiple Hitachi and related IT management products, including JP1/IT Desktop Management versions, Job Management Partner 1 suite components, and JP1/NETM/DM software on Windows platforms. The vulnerability impacts numerous version branches across products, with affected versions ranging from version 09-00 through 13-50, with patched versions available for most product lines. SEVERITY This vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and valid user credentials to exploit. The attack requires no user interaction and affects the confidentiality, integrity, and availability of the target system. The metric vector indicates an authenticated attacker can achieve full compromise of affected systems remotely. EXPLOITATION STATUS Currently, CVE-2025-65115 is not listed on the CISA Known Exploited Vulnerabilities catalog and is inactive on the Hot List, suggesting no active exploitation in the wild at this time. The EPSS score of 0.00081 ranks this vulnerability below the typical exploitation threshold, and no public exploit code has been reported. However, the moderate FAUCET Risk Score of 52.0 and the broad product portfolio affected warrant prioritized patching and monitoring given the high severity rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 09-50, <= 09-50-03CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | ||
>= 09-51, <= 09-51-05CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | ||
>= 10-00, <= 10-00-02CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | ||
>= 10-01, <= 10-01-05CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | ||
>= 10-02, <= 10-02-05CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.