216.73.217.22

CVE-2025-4427

· Published 19/05/2025 02:00 · Modified 21/12/2025 14:23 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2025-4427

Essential information

Published
19/05/2025 02:00
Modified
21/12/2025 14:23
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:L/I:N/A:N

CVSS metrics

Description

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

NVD status

NVD
View on NVD