CVE-2025-6996
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
HIGH · CVSS 8.4
EPSS 0.00094
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0