CVE-2025-6996
8.4Ivanti · Endpoint Manager
Ivanti Endpoint Manager contains an improper encryption flaw that allows a local authenticated attacker to decrypt sensitive user passwords.
Executive summary
A critical vulnerability in Ivanti Endpoint Manager permits local authenticated attackers to decrypt sensitive user credentials, posing a severe risk to internal account security.
Vulnerability
The software suffers from improper storage of passwords in a recoverable format (CWE-257). A local authenticated attacker can leverage this flaw to decrypt passwords belonging to other system users.
Business impact
The ability for an attacker to decrypt other users' passwords constitutes a total loss of confidentiality for credentials stored within the agent. Given the CVSS score of 8.4, this vulnerability represents a high risk, as it facilitates lateral movement and privilege escalation within the environment. Unauthorized access to these credentials could lead to widespread system compromise and significant operational disruption.
Remediation
Immediate Action: Update Ivanti Endpoint Manager to version 2024 SU3, 2022 SU8 Security Update 1, or a later supported release to resolve the encryption vulnerability.
Proactive Monitoring: Review system access logs for unauthorized attempts to access or modify agent configuration files or associated credential stores.
Compensating Controls: Restrict local system access to authorized personnel only and enforce the principle of least privilege for all local accounts to limit the potential scope of an authenticated attack.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a significant risk to the integrity of user credentials within the Ivanti environment. IT administrators should prioritize the deployment of the security updates provided by Ivanti to ensure that password storage mechanisms are properly secured. Immediate patching is essential to prevent potential credential theft and subsequent unauthorized access to sensitive systems.