CVE-2025-4427
KEVmoderateAuthentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) API
CISA: Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
Ivanti Endpoint Manager Mobile (EPMM), Ivanti's on-premises mobile device management platform, contains an authentication bypass (CWE-288) in its API component caused by an insecure implementation of the Spring Framework library. An unauthenticated attacker can send crafted API requests to access protected resources without valid credentials. Successful exploitation grants access to sensitive management functionality and data in the MDM platform, which could serve as a foothold for further compromise of a managed-device estate. Any organization running Ivanti EPMM is potentially affected, particularly where the API is reachable from the internet or untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-05-19 and carries an EPSS probability of 99.9% of being exploited within 30 days.
What to do: Upgrade EPMM to the patched releases specified in Ivanti's advisory (exact version numbers were not included in the source data), prioritizing internet-facing instances; federal agencies must apply the required action per BOD 22-01 or follow vendor mitigation guidance or discontinue use if mitigations are unavailable. Review API and web server logs for unauthenticated access to protected resources to check for compromise, since CISA's KEV listing confirms active exploitation. No public proof-of-concept is known, but with EPSS at 99.9% treat this as an urgent patch.
| Ivanti Endpoint Manager Mobile (EPMM) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
- Affected
- Ivanti Endpoint Manager Mobile (EPMM)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- endpoint manager mobile
- Weakness
- CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N