S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated May 15, 2025

CVE-2025-4427 Scanner

CVE-2025-4427 Scanner - Remote Code Execution vulnerability in Ivanti Endpoint Manager Mobile

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-4427
7.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Endpoint Manager Mobileby Ivanti
12.5.0.1
Updated Aug 5, 2026View on NVD →
Detail

Ivanti Endpoint Manager Mobile is a comprehensive tool used by enterprises to manage and secure mobile devices across various platforms. It is utilized by IT departments to enforce security policies, manage device configurations, and ensure compliance within corporate networks. This product supports a wide range of mobile operating systems, allowing centralized control over mobile assets. Organizations leverage this tool to maintain data security while enabling mobile productivity. The platform offers functionalities such as application distribution and platform updates, ensuring devices are operating efficiently. Ivanti's Endpoint Manager Mobile is a key component in enterprise mobility management solutions.

The vulnerability in question is a Remote Code Execution (RCE) flaw. It occurs due to an authentication bypass that permits attackers to access protected resources without proper credentials. The issue stems from unsafe user input within a specific bean validator, susceptible to Server-Side Template Injection. This allows remote attackers to execute arbitrary code on affected systems. Exploiting this vulnerability could lead to unauthorized access and control over the mobile device manager. Such vulnerabilities are serious, as they can compromise the security of entire networks reliant on the affected software.

Technical details of the vulnerability include unsafe user input being fed into a bean validator, which acts as a sink for Server-Side Template Injection. Specific endpoints related to 'featureusage_history' and 'featureusage' are exploited by sending crafted requests. These requests leverage Java's reflective capabilities to invoke Runtime executions. The exploit involves sending code to a vulnerable parameter that allows command execution via interactions with DNS protocol channels. The vulnerability relies on the ability to bypass authentication mechanisms, potentially because of weak credential validation.

If exploited, the vulnerability can have severe consequences for affected organizations. Malicious actors may execute remote code, gaining control over deployed devices and sensitive data. This could result in data theft, unauthorized access to internal networks, service disruptions, and an overall compromise of enterprise security. Organizations may incur financial losses, reputational damage, and legal implications as a result of breached confidentiality, integrity, and availability. Furthermore, exploited systems could become vectors for further attacks, amplifying the reach of the threat.

REFERENCES

Solution Advice
  • Apply the latest patches provided by Ivanti to address this vulnerability.
  • Ensure secure authentication mechanisms are in place to prevent credential bypass.
  • Limit network exposure for the mobile manager to only necessary systems and services.
  • Regularly audit and monitor system logs for any suspicious activities.
  • Implement network segmentation to limit the impact of potential exploitations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.