CyberICT

CVE-2025-4427

Ivanti · Published May 13, 2025

CVSS v3.1

HIGH
Patch availableGet patch

Description

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

Affected Products

  • Endpoint Manager Mobile < 11.12.0.5
  • Endpoint Manager Mobile < 12.3.0.2
  • Endpoint Manager Mobile < 12.4.0.2
  • Endpoint Manager Mobile

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N