CVE-2025-4427
🔥 Known Exploited (CISA KEV)MEDIUM
5.3
CVSS Severity Score
Vulnerability Description
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
Affected Platforms (CPE)
📦
Ivanti
Endpoint Manager Mobile
< 11.12.0.5>= 12.3.0.0 and < 12.3.0.2>= 12.4.0.0 and < 12.4.0.2= 12.5.0.0
