CVE-2025-4427
Ivanti · Published May 13, 2025
7.5
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
Affected Products
- Endpoint Manager Mobile < 11.12.0.5
- Endpoint Manager Mobile < 12.3.0.2
- Endpoint Manager Mobile < 12.4.0.2
- Endpoint Manager Mobile
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N