CVE-2025-6995
8.4Ivanti · Endpoint Manager
Ivanti Endpoint Manager contains a vulnerability involving improper encryption that allows a local authenticated attacker to decrypt user passwords.
Executive summary
Ivanti Endpoint Manager contains a flaw in its agent encryption that permits local authenticated attackers to decrypt sensitive user credentials, posing a significant risk to organizational identity security.
Vulnerability
This vulnerability is caused by the storage of passwords in a recoverable format, identified as CWE-257. An attacker with local authenticated access to the agent can exploit this flaw to perform unauthorized decryption of credentials belonging to other users.
Business impact
The ability for a local user to decrypt the passwords of other users within the Ivanti Endpoint Manager environment constitutes a high-severity risk. Given the CVSS score of 8.4, this vulnerability could lead to widespread credential theft, unauthorized lateral movement, and complete compromise of user accounts managed by the platform.
Remediation
Immediate Action: Update Ivanti Endpoint Manager to version 2024 SU3, 2022 SU8 Security Update 1, or a later version to remediate the encryption flaw.
Proactive Monitoring: Review local system logs for unusual authentication activity or evidence of unauthorized access to agent-related configuration files and directories.
Compensating Controls: Restrict local system access to authorized personnel only and enforce the principle of least privilege to minimize the number of users capable of interacting with the agent environment.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a critical risk to the security of managed endpoints and the confidentiality of user credentials. Administrators should prioritize patching all instances of Ivanti Endpoint Manager to the specified fixed versions immediately to prevent potential exploitation by malicious local actors.