Medium severity5.3CISA KEVNVD Advisory· Published May 13, 2025· Updated Jun 17, 2026
CVE-2025-4427
CVE-2025-4427
Description
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*range: <11.12.0.5
- cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.0.0:*:*:*:*:*:*:*
- (no CPE)range: <=12.5.0.0
- (no CPE)range: 12.5.0.1
Patches
Vulnerability mechanics
References
2- forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMMnvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers nowRisky Business · May 21, 2025