CVE-2025-4428 is a critical Remote Code Execution vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior, allowing authenticated attackers to execute arbitrary code via crafted API requests. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog and extensive media coverage detailing its use by threat actors. Exploit modules are available, including a Metasploit module, and it has garnered substantial community discussion, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.12.0.5CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | ||
>= 12.3.0.0, < 12.3.0.2CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | ||
>= 12.4.0.0, < 12.4.0.2CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | ||
12.5.0.0CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.