ENISA EU KEV catalog membership for CVE-2025-4427
ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.
Vulnerability threat dossier
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
VTP analyst assessment
Medium-severity authentication bypass in Ivanti EPMM 12.5.0.0 and earlier permits unauthenticated access to protected API resources. Supplied KEV context and independent ENISA EU KEV evidence establish known global exploitation.
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.
The supplied evidence does not identify which protected resources are exposed or whether additional impact requires another flaw.
Local API exposure, version state, and compromise are unknown without first-party telemetry.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
EPMM 12.5.0.0 or earlier with API endpoints reachable from untrusted networks.
VTP deterministic assessment
CISA KEV lists this vulnerability as known to be exploited globally.
EPSS is 1.00; this is predictive context, not exploitation evidence.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Material change ledger
Claim provenance
1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Event history
CISA lists global known exploitation. This is not a VTP sensor observation.
ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.
Original publications
ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.
Technical vulnerability data
Raw observations
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.