CVE-2025-4427
13.05.2025, 16:15
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.Enginsight
Vendor | Product | Version |
---|---|---|
ivanti | endpoint_manager_mobile | 𝑥 < 11.12.0.5 |
ivanti | endpoint_manager_mobile | 12.3.0.0 ≤ 𝑥 < 12.3.0.2 |
ivanti | endpoint_manager_mobile | 12.4.0.0 ≤ 𝑥 < 12.4.0.2 |
ivanti | endpoint_manager_mobile | 12.5.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
Vulnerability Media Exposure