HIGH
CVE-2025-4427
CVSS
7.5
KEV
Description
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
Summary dbcve.org
Authentication bypass vulnerability in the API component of Ivanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior versions. Attackers can access protected resources through the API without proper credentials by exploiting insufficient authentication checks.
Mitigation
Upgrade Ivanti Endpoint Manager Mobile to a version beyond 12.5.0.0 or apply vendor-supplied patches. Until patching is complete, implement network-level access controls to restrict unauthorized access to the API endpoints.
Weakness (CWE)
CWE-288
EPSS Score
99.93%
Probability of exploitation in next 30 days
100th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.