← Back

CVE-2025-4427

Published: May 13, 2025Modified: Oct 24, 2025CISA KEV

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

Affected (4)

1 product
Endpoint Manager Mobile
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Before 11.12.0.5
From 12.3.0.0 to 12.3.0.2
From 12.4.0.0 to 12.4.0.2
Version 12.5.0.0

References (2)

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.