An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API. | |
Title | Authentication Bypass | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ivanti
Published: 2025-05-13T15:45:35.145Z
Updated: 2025-05-13T16:29:05.756Z
Reserved: 2025-05-08T07:50:50.421Z
Link: CVE-2025-4427

Updated: 2025-05-13T16:29:01.149Z

Status : Awaiting Analysis
Published: 2025-05-13T16:15:32.330
Modified: 2025-05-13T19:35:18.080
Link: CVE-2025-4427

No data.