CVE-2025-4427

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ivantiCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
ivantiendpoint_manager_mobile
𝑥
< 11.12.0.5
ivantiendpoint_manager_mobile
12.3.0.0 ≤
𝑥
< 12.3.0.2
ivantiendpoint_manager_mobile
12.4.0.0 ≤
𝑥
< 12.4.0.2
ivantiendpoint_manager_mobile
12.5.0.0
𝑥
= Vulnerable software versions