Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

cve CVE-2025-4427 3 sources, 3 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://forums.ivanti.com/s/article/Sec… the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBİbrahimsql
receipt
Source
Exploit-DB
Its words
İbrahimsql
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "İbrahimsql",
  "codes": "CVE-2025-4427",
  "date_added": "2025-08-26",
  "date_published": "2025-08-26",
  "date_updated": "2025-08-26",
  "description": "Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass",
  "file": "exploits/multiple/remote/52421.py",
  "id": "52421",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "remote",
  "verified": "0"
}
—
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-288
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-288
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-4427",
  "cwes": "CWE-288",
  "dateAdded": "2025-05-19",
  "dueDate": "2025-06-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
  "product": "Endpoint Manager Mobile (EPMM)",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
  "vendorProject": "Ivanti",
  "vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2025-06-09
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2025-06-09
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-4427",
  "cwes": "CWE-288",
  "dateAdded": "2025-05-19",
  "dueDate": "2025-06-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
  "product": "Endpoint Manager Mobile (EPMM)",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
  "vendorProject": "Ivanti",
  "vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-4427",
  "cwes": "CWE-288",
  "dateAdded": "2025-05-19",
  "dueDate": "2025-06-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
  "product": "Endpoint Manager Mobile (EPMM)",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
  "vendorProject": "Ivanti",
  "vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-4427",
  "cwes": "CWE-288",
  "dateAdded": "2025-05-19",
  "dueDate": "2025-06-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
  "product": "Endpoint Manager Mobile (EPMM)",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
  "vendorProject": "Ivanti",
  "vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-4427",
  "cwes": "CWE-288",
  "dateAdded": "2025-05-19",
  "dueDate": "2025-06-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
  "product": "Endpoint Manager Mobile (EPMM)",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
  "vendorProject": "Ivanti",
  "vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
}
—
Platform
platform
not compared
Exploit-DBmultiple
receipt
Source
Exploit-DB
Its words
multiple
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "İbrahimsql",
  "codes": "CVE-2025-4427",
  "date_added": "2025-08-26",
  "date_published": "2025-08-26",
  "date_updated": "2025-08-26",
  "description": "Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass",
  "file": "exploits/multiple/remote/52421.py",
  "id": "52421",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "remote",
  "verified": "0"
}
—
Platform
platform
not compared
Metasploit exploit modulesPython
receipt
Source
Metasploit exploit modules
Its words
Python
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "python",
  "author": [
    "CERT-EU",
    "Sonny Macdonald",
    "Piotr Bazydlo",
    "remmons-r7"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits an unauthenticated remote code execution exploit chain for Ivanti EPMM,\n          tracked as CVE-2025-4427 and CVE-2025-4428. An authentication flaw permits unauthenticated\n          access to an administrator web API endpoint, which allows for code execution via expression\n          language injection. This module executes in the context of the 'tomcat' user. This module\n          should also work on many versions of MobileIron Core (rebranded as Ivanti EPMM).",
  "disclosure_date": "2025-05-13",
  "fullname": "exploit/multi/http/ivanti_epmm_rce_cve_2025_4427_4428",
  "is_install_path": true,
  "mod_time": "2026-06-02 10:32:30 +0000",
  "name": "Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/ivanti_epmm_rce_cve_2025_4427_4428.rb",
  "platform": "Python",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/ivanti_epmm_rce_cve_2025_4427_4428",
  "references": [
    "CVE-2025-4427",
    "EDB-52421",
    "CVE-2025-4428",
    "URL-https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US",
    "URL-https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428",
    "URL-https://blog.eclecticiq.com/china-nexus-threat-actor-actively-exploiting-ivanti-endpoint-manager-mobile-cve-2025-4428-vulnerability"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Default"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesEndpoint Manager Mobile (EPMM)
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Endpoint Manager Mobile (EPMM)
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-4427",
  "cwes": "CWE-288",
  "dateAdded": "2025-05-19",
  "dueDate": "2025-06-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
  "product": "Endpoint Manager Mobile (EPMM)",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
  "vendorProject": "Ivanti",
  "vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "python",
  "author": [
    "CERT-EU",
    "Sonny Macdonald",
    "Piotr Bazydlo",
    "remmons-r7"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits an unauthenticated remote code execution exploit chain for Ivanti EPMM,\n          tracked as CVE-2025-4427 and CVE-2025-4428. An authentication flaw permits unauthenticated\n          access to an administrator web API endpoint, which allows for code execution via expression\n          language injection. This module executes in the context of the 'tomcat' user. This module\n          should also work on many versions of MobileIron Core (rebranded as Ivanti EPMM).",
  "disclosure_date": "2025-05-13",
  "fullname": "exploit/multi/http/ivanti_epmm_rce_cve_2025_4427_4428",
  "is_install_path": true,
  "mod_time": "2026-06-02 10:32:30 +0000",
  "name": "Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/ivanti_epmm_rce_cve_2025_4427_4428.rb",
  "platform": "Python",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/ivanti_epmm_rce_cve_2025_4427_4428",
  "references": [
    "CVE-2025-4427",
    "EDB-52421",
    "CVE-2025-4428",
    "URL-https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US",
    "URL-https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428",
    "URL-https://blog.eclecticiq.com/china-nexus-threat-actor-actively-exploiting-ivanti-endpoint-manager-mobile-cve-2025-4428-vulnerability"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Default"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBremote
receipt
Source
Exploit-DB
Its words
remote
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "İbrahimsql",
  "codes": "CVE-2025-4427",
  "date_added": "2025-08-26",
  "date_published": "2025-08-26",
  "date_updated": "2025-08-26",
  "description": "Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass",
  "file": "exploits/multiple/remote/52421.py",
  "id": "52421",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "remote",
  "verified": "0"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesIvanti
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Ivanti
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 20:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-4427",
  "cwes": "CWE-288",
  "dateAdded": "2025-05-19",
  "dueDate": "2025-06-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4427",
  "product": "Endpoint Manager Mobile (EPMM)",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.",
  "vendorProject": "Ivanti",
  "vulnerabilityName": "Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "İbrahimsql",
  "codes": "CVE-2025-4427",
  "date_added": "2025-08-26",
  "date_published": "2025-08-26",
  "date_updated": "2025-08-26",
  "description": "Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass",
  "file": "exploits/multiple/remote/52421.py",
  "id": "52421",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "remote",
  "verified": "0"
}
—

vulnerability

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
zetlyn/cve-kev · 2025-05-19
cwes CWE-288 due_date 2025-06-09 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Endpoint Manager Mobile (EPMM) vendor_project Ivanti

exploit

Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
zetlyn/cve-metasploit · 2025-05-13
platform Python rank 600 source
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
zetlyn/cve-exploitdb · 2025-08-26
author İbrahimsql platform multiple type remote verified false source