ZeroHour

CVE-2025-4427

KEVmoderate

Authentication Bypass in Ivanti Endpoint Manager Mobile (EPMM) API

CISA: Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

CVSS 3.1
7.5 high
EPSS
100%p100
Published
()
KEV added
AI analysis

Ivanti Endpoint Manager Mobile (EPMM), Ivanti's on-premises mobile device management platform, contains an authentication bypass (CWE-288) in its API component caused by an insecure implementation of the Spring Framework library. An unauthenticated attacker can send crafted API requests to access protected resources without valid credentials. Successful exploitation grants access to sensitive management functionality and data in the MDM platform, which could serve as a foothold for further compromise of a managed-device estate. Any organization running Ivanti EPMM is potentially affected, particularly where the API is reachable from the internet or untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-05-19 and carries an EPSS probability of 99.9% of being exploited within 30 days.

What to do: Upgrade EPMM to the patched releases specified in Ivanti's advisory (exact version numbers were not included in the source data), prioritizing internet-facing instances; federal agencies must apply the required action per BOD 22-01 or follow vendor mitigation guidance or discontinue use if mitigations are unavailable. Review API and web server logs for unauthenticated access to protected resources to check for compromise, since CISA's KEV listing confirms active exploitation. No public proof-of-concept is known, but with EPSS at 99.9% treat this as an urgent patch.

Affected
Ivanti Endpoint Manager Mobile (EPMM)
Estimated exposure
moderate≈1,000–3,000 internet-exposed EPMM instances; total on-prem enterprise deployments likely in the low tens of thousands (estimate) — Ivanti EPMM is enterprise on-premises MDM software rather than mass-market software, and public internet-wide scans have historically shown on the order of a few thousand exposed EPMM/MobileIron instances, so the exposed-system count is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

CISA Known Exploited Vulnerability
Affected
Ivanti Endpoint Manager Mobile (EPMM)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
endpoint manager mobile
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news