Security
Loading…

CVE-2025-4427

UNKNOWNKnown Exploited
Description

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

Timeline
Published:May 19th, 2025 12:00 AM
Last modified:May 19th, 2025 12:00 AM
Added to KEV:May 19th, 2025
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Ivanti

Products

Endpoint Manager Mobile (EPMM)
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute