CVE-2025-6995

8.4HIGH

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

Published: 7/8/2025Updated: 7/11/2025

Description

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

AI AnalysisPowered by AI

Affected Products

ivantiendpoint_manager
ivantiendpoint_manager
2022
ivantiendpoint_manager
2022
ivantiendpoint_manager
2022
ivantiendpoint_manager
2022
ivantiendpoint_manager
2022
ivantiendpoint_manager
2022
ivantiendpoint_manager
2022
ivantiendpoint_manager
2022
ivantiendpoint_manager
2022
ivantiendpoint_manager
2024
ivantiendpoint_manager
2024
ivantiendpoint_manager
2024

References