HIGH

CVE-2025-4427

Ivanti Endpoint Manager Mobile 2025-05-13 CVSS v3.1
CVSS
7.5
KEV

Description

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

Summary dbcve.org

Authentication bypass vulnerability in the API component of Ivanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior versions. Attackers can access protected resources through the API without proper credentials by exploiting insufficient authentication checks.

Mitigation

Upgrade Ivanti Endpoint Manager Mobile to a version beyond 12.5.0.0 or apply vendor-supplied patches. Until patching is complete, implement network-level access controls to restrict unauthorized access to the API endpoints.

Weakness (CWE)

CWE-288

EPSS Score

99.93%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE