Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
cve CVE-2025-4427 3 sources, 3 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://forums.ivanti.com/s/article/Sec… the claim
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://forums.ivanti.com/s/article/Sec… the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | İbrahimsqlreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "İbrahimsql",
"codes": "CVE-2025-4427",
"date_added": "2025-08-26",
"date_published": "2025-08-26",
"date_updated": "2025-08-26",
"description": "Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass",
"file": "exploits/multiple/remote/52421.py",
"id": "52421",
"platform": "multiple",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "remote",
"verified": "0"
} | — |
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-288receipt
What the source handed over{
"cveID": "CVE-2025-4427",
"cwes": "CWE-288",
"dateAdded": "2025-05-19",
"dueDate": "2025-06-09",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
"product": "Endpoint Manager Mobile (EPMM)",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
"vendorProject": "Ivanti",
"vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2025-06-09receipt
What the source handed over{
"cveID": "CVE-2025-4427",
"cwes": "CWE-288",
"dateAdded": "2025-05-19",
"dueDate": "2025-06-09",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
"product": "Endpoint Manager Mobile (EPMM)",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
"vendorProject": "Ivanti",
"vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2025-4427",
"cwes": "CWE-288",
"dateAdded": "2025-05-19",
"dueDate": "2025-06-09",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
"product": "Endpoint Manager Mobile (EPMM)",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
"vendorProject": "Ivanti",
"vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2025-4427",
"cwes": "CWE-288",
"dateAdded": "2025-05-19",
"dueDate": "2025-06-09",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
"product": "Endpoint Manager Mobile (EPMM)",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
"vendorProject": "Ivanti",
"vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2025-4427",
"cwes": "CWE-288",
"dateAdded": "2025-05-19",
"dueDate": "2025-06-09",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
"product": "Endpoint Manager Mobile (EPMM)",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
"vendorProject": "Ivanti",
"vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
} | — |
| Platform platform not compared | Exploit-DB | multiplereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "İbrahimsql",
"codes": "CVE-2025-4427",
"date_added": "2025-08-26",
"date_published": "2025-08-26",
"date_updated": "2025-08-26",
"description": "Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass",
"file": "exploits/multiple/remote/52421.py",
"id": "52421",
"platform": "multiple",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "remote",
"verified": "0"
} | — |
| Platform platform not compared | Metasploit exploit modules | Pythonreceipt
What the source handed over{
"aliases": [],
"arch": "python",
"author": [
"CERT-EU",
"Sonny Macdonald",
"Piotr Bazydlo",
"remmons-r7"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module exploits an unauthenticated remote code execution exploit chain for Ivanti EPMM,\n tracked as CVE-2025-4427 and CVE-2025-4428. An authentication flaw permits unauthenticated\n access to an administrator web API endpoint, which allows for code execution via expression\n language injection. This module executes in the context of the 'tomcat' user. This module\n should also work on many versions of MobileIron Core (rebranded as Ivanti EPMM).",
"disclosure_date": "2025-05-13",
"fullname": "exploit/multi/http/ivanti_epmm_rce_cve_2025_4427_4428",
"is_install_path": true,
"mod_time": "2026-06-02 10:32:30 +0000",
"name": "Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/ivanti_epmm_rce_cve_2025_4427_4428.rb",
"platform": "Python",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/ivanti_epmm_rce_cve_2025_4427_4428",
"references": [
"CVE-2025-4427",
"EDB-52421",
"CVE-2025-4428",
"URL-https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US",
"URL-https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428",
"URL-https://blog.eclecticiq.com/china-nexus-threat-actor-actively-exploiting-ivanti-endpoint-manager-mobile-cve-2025-4428-vulnerability"
],
"rport": 443,
"session_types": false,
"targets": [
"Default"
],
"type": "exploit"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | Endpoint Manager Mobile (EPMM)receipt
What the source handed over{
"cveID": "CVE-2025-4427",
"cwes": "CWE-288",
"dateAdded": "2025-05-19",
"dueDate": "2025-06-09",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
"product": "Endpoint Manager Mobile (EPMM)",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
"vendorProject": "Ivanti",
"vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "python",
"author": [
"CERT-EU",
"Sonny Macdonald",
"Piotr Bazydlo",
"remmons-r7"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module exploits an unauthenticated remote code execution exploit chain for Ivanti EPMM,\n tracked as CVE-2025-4427 and CVE-2025-4428. An authentication flaw permits unauthenticated\n access to an administrator web API endpoint, which allows for code execution via expression\n language injection. This module executes in the context of the 'tomcat' user. This module\n should also work on many versions of MobileIron Core (rebranded as Ivanti EPMM).",
"disclosure_date": "2025-05-13",
"fullname": "exploit/multi/http/ivanti_epmm_rce_cve_2025_4427_4428",
"is_install_path": true,
"mod_time": "2026-06-02 10:32:30 +0000",
"name": "Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/ivanti_epmm_rce_cve_2025_4427_4428.rb",
"platform": "Python",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/ivanti_epmm_rce_cve_2025_4427_4428",
"references": [
"CVE-2025-4427",
"EDB-52421",
"CVE-2025-4428",
"URL-https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US",
"URL-https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428",
"URL-https://blog.eclecticiq.com/china-nexus-threat-actor-actively-exploiting-ivanti-endpoint-manager-mobile-cve-2025-4428-vulnerability"
],
"rport": 443,
"session_types": false,
"targets": [
"Default"
],
"type": "exploit"
} | — |
| Type type | Exploit-DB | remotereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "İbrahimsql",
"codes": "CVE-2025-4427",
"date_added": "2025-08-26",
"date_published": "2025-08-26",
"date_updated": "2025-08-26",
"description": "Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass",
"file": "exploits/multiple/remote/52421.py",
"id": "52421",
"platform": "multiple",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "remote",
"verified": "0"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Ivantireceipt
What the source handed over{
"cveID": "CVE-2025-4427",
"cwes": "CWE-288",
"dateAdded": "2025-05-19",
"dueDate": "2025-06-09",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
"product": "Endpoint Manager Mobile (EPMM)",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
"vendorProject": "Ivanti",
"vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "İbrahimsql",
"codes": "CVE-2025-4427",
"date_added": "2025-08-26",
"date_published": "2025-08-26",
"date_updated": "2025-08-26",
"description": "Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass",
"file": "exploits/multiple/remote/52421.py",
"id": "52421",
"platform": "multiple",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "remote",
"verified": "0"
} | — |
vulnerability
| Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability zetlyn/cve-kev · 2025-05-19 | cwes CWE-288 due_date 2025-06-09 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Endpoint Manager Mobile (EPMM) vendor_project Ivanti |
exploit
| Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution zetlyn/cve-metasploit · 2025-05-13 | platform Python rank 600 | source |
| Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass zetlyn/cve-exploitdb · 2025-08-26 | author İbrahimsql platform multiple type remote verified false | source |