← Back to browse · API

CVE-2025-4427

Severity
MEDIUM
CVSS
5.3
EPSS
0.99908
Risk score
81.17
CISA KEV
Yes
PoC
No
Published
2025-05-19
Modified
2025-05-19
First seen
2026-08-07
Aliases
EUVD-2025-14388, GHSA-9WCP-Q959-7MQ8
Products
Ivanti:Endpoint Manager Mobile (EPMM), Ivanti:Endpoint Manager Mobile patch: 12.5.0.1
Sources
euvd EUVD-2025-14388
cisa.gov CVE-2025-4427

Description

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

References