CVE-2025-4427 is a critical authentication bypass vulnerability affecting the API component of Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior. This flaw allows unauthenticated attackers to access protected resources, posing a significant risk to confidentiality. With a CVSS score of 7.5 (High), it is easily exploitable over the network with low attack complexity and no user interaction required. The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and Nuclei templates, and has garnered extensive community discussion and media coverage, including reports of nation-state actor exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.12.0.5CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | ||
>= 12.3.0.0, < 12.3.0.2CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | ||
>= 12.4.0.0, < 12.4.0.2CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* | ||
12.5.0.0CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.