CVE-2025-4427

Source
https://cve.org/CVERecord?id=CVE-2025-4427
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4427.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-4427
Published
2025-05-13T16:15:32.330Z
Modified
2026-03-13T03:17:51.680254Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "11.12.0.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "12.3.0.0"
            },
            {
                "fixed": "12.3.0.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "12.4.0.0"
            },
            {
                "fixed": "12.4.0.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.5.0.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4427.json"