LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-4427: Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 19, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 9, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-4427 to its Known Exploited Vulnerabilities catalog on May 19, 2025, with a federal patch deadline of Jun 9, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted…

What this vulnerability is

CVE-2025-4427 is an authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM). It affects the API component and lets an attacker reach protected resources without valid credentials by sending crafted API requests. The issue stems from an insecure implementation of the Spring Framework open-source library.

EPMM is used to manage mobile devices and endpoints in enterprise environments. Successful abuse of this flaw can give unauthorized access to management functions or data that should require authentication, which is why IT and security teams need to treat it as a priority for inventory, patching, and monitoring.

How it works

The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). In this case, the API component of Ivanti EPMM does not correctly enforce authentication for certain requests because of how the Spring Framework is implemented. An attacker who can reach the API can craft requests that skip normal credential checks and obtain access to resources that should be protected.

Public detail does not describe the exact request format or parameters. Defenders should treat any unauthenticated or anomalous API traffic to EPMM as potentially related and confirm the precise attack surface against the vendor advisory. The weakness is in authentication enforcement rather than a remote code execution primitive, but the resulting unauthorized access can still enable further compromise of managed devices or stored configuration data.

Am I affected? How to find it in your systems

Ivanti Endpoint Manager Mobile (EPMM) is typically deployed as an on-premises or cloud-hosted mobile device management (MDM) solution that communicates with enrolled endpoints and administrative consoles via APIs. Look for servers or virtual appliances running EPMM, often identified by product names, listening ports associated with the management interface, or network traffic to known EPMM endpoints.

If you cannot determine exposure from internal records, treat any EPMM instance that has not been explicitly patched or mitigated as potentially affected until verified against the vendor advisory.

How to remediate

Apply the vendor-supplied update or mitigation for CVE-2025-4427 as the primary remediation step. Follow the instructions published by Ivanti for EPMM; CISA also directs organizations to apply mitigations per vendor guidance, follow applicable BOD 22-01 requirements for cloud services, or discontinue use of the product if mitigations are unavailable.

Document the change and re-scan to confirm the vulnerability is no longer present.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that limit reachability and detect abuse of the authentication bypass.

These measures lower risk but do not replace the vendor patch. Plan to apply the official update as soon as operationally feasible.

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities can lead to unauthorized access and subsequent data exposure or further compromise of managed devices. Known ransomware use of this specific CVE is not documented. If you suspect your EPMM instance was reached by unauthenticated requests, review access logs for indicators of compromise, rotate any credentials or tokens that may have been accessible, and assess whether enrolled devices or stored configuration data require additional scrutiny. You can also run a free exposure scan of your email addresses against known breach data sets to check whether related accounts appear in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager Mobile (EPMM)
WeaknessCWE-288
Added to CISA KEVMay 19, 2025
Federal patch deadlineJun 9, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities