Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 9, 2025

CVE-2025-4427

High
EPSS 91.6%CISA KEV
Ivanti/Endpoint Manager Mobile (EPMM)

Description

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

EPSS — Exploit Probability

91.6%

Higher than 99.7% of all CVEs

Required Action

https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
91.6%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

May 19, 2025

Added to KEV

May 19, 2025

Remediation Due

Jun 9, 2025

Affected Product

Ivanti

Endpoint Manager Mobile (EPMM)

View all Ivanti CVEs