8.4

CVE-2025-6996

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IvantiEndpoint Manager Version < 2022
IvantiEndpoint Manager Version2022 Update-
IvantiEndpoint Manager Version2022 Updatesu1
IvantiEndpoint Manager Version2022 Updatesu2
IvantiEndpoint Manager Version2022 Updatesu3
IvantiEndpoint Manager Version2022 Updatesu4
IvantiEndpoint Manager Version2022 Updatesu5
IvantiEndpoint Manager Version2022 Updatesu6
IvantiEndpoint Manager Version2022 Updatesu7
IvantiEndpoint Manager Version2022 Updatesu8
IvantiEndpoint Manager Version2024 Update-
IvantiEndpoint Manager Version2024 Updatesu1
IvantiEndpoint Manager Version2024 Updatesu2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.165
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
3c1d8aa1-5a33-4ea4-8992-aadd6440af75 8.4 2 5.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CWE-257 Storing Passwords in a Recoverable Format

The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.