CVE-2025-4427

EUVD-2025-14388
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ivantiCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
ivantiendpoint_manager_mobile
𝑥
< 11.12.0.5
ivantiendpoint_manager_mobile
12.3.0.0 ≤
𝑥
< 12.3.0.2
ivantiendpoint_manager_mobile
12.4.0.0 ≤
𝑥
< 12.4.0.2
ivantiendpoint_manager_mobile
12.5.0.0
𝑥
= Vulnerable software versions