V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-4427
CVE
High KEVConfirmedExploit available

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected res…

CVSS
7.5
High
EPSS
1.00
p99
Published
2025-01-01
Updated
2025-05-19
Description

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

Tags · CWE
KEVPre-authAuth bypass
CWE-288
CAPEC-127
CAPEC-665
Affected products
Endpoint_manager_mobile < 11.12.0.5Endpoint_manager_mobile 12.3.0.0–12.3.0.2Endpoint_manager_mobile 12.4.0.0–12.4.0.2Endpoint_manager_mobile
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2025-01-01
Published
2025-05-19
Added to KEV
2025-05-19
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.996 · p99
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-127 · CWE-288
└ via CAPEC-665 · CWE-288
└ via CAPEC-665 · CWE-288
└ via CAPEC-665 · CWE-288
Known exploits — Сканер-ВС
52421
exploitdb · https://www.exploit-db.com/exploits/52421
Enterprise
CVE-2025-4427
github-poc · https://github.com/rxerium/CVE-2025-4427-CVE-2025-4428
Enterprise
Affected products
ProductVendorStatus
endpoint_manager_mobile*Exploited
Source databases
CVE
Related vulnerabilities