CVE-2025-4427: Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
Other sources
Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4427?
CVE-2025-4427 is classified as a critical vulnerability due to its potential for authentication bypass.
Who is affected by CVE-2025-4427?
CVE-2025-4427 affects Ivanti Endpoint Manager Mobile versions 12.5.0.0 and earlier.
How does CVE-2025-4427 exploit the Ivanti Endpoint Manager Mobile?
CVE-2025-4427 allows attackers to access protected resources without proper credentials via the API.
How do I fix CVE-2025-4427?
To mitigate CVE-2025-4427, it is recommended to upgrade to a patched version of Ivanti Endpoint Manager Mobile.
What are the risks of CVE-2025-4427 if not addressed?
If CVE-2025-4427 is not addressed, unauthorized users may gain access to sensitive information and resources.