Executive brief
Ivanti Endpoint Manager Mobile (EPMM), a platform used by organizations to manage and secure mobile devices, contains a vulnerability that allows unauthorized individuals to bypass security checks. By sending specifically crafted requests to the system's programming interface (API), an attacker can access sensitive internal resources without needing a username or password. This flaw is reportedly being exploited in the wild, posing a significant risk to corporate data and mobile device management operations.
Technical details
An authentication bypass vulnerability (CWE-288) exists in the API component of Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and prior. The root cause is attributed to an insecure implementation of the Spring Framework open-source library. A remote, unauthenticated attacker can exploit this by sending crafted API requests to bypass credential requirements and access protected resources. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Patches or mitigations are available from the vendor to address the insecure API handling.
Affected products
- Ivanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior; specifically versions up to 11.12.0.5, 12.3.0.0 to 12.3.0.2, and 12.4.0.0 to 12.4.0.2
Timeline
- 2025-05-13: disclosed: Initial CVE entry received from Ivanti
- 2025-05-19: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-05-19: advisory: Vendor advisory published by Ivanti