216.73.217.22

CVE-2025-4428

· Published 19/05/2025 02:00 · Modified 21/12/2025 14:23 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2025-4428

Essential information

Published
19/05/2025 02:00
Modified
21/12/2025 14:23
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
7.2 HIGH (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.

NVD status

NVD
View on NVD