CVE-2025-22459: Medium severity ivanti endpoint manager (epm) vulnerability
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22459?
CVE-2025-22459 has been classified as a medium severity vulnerability due to its potential impact on data integrity and confidentiality.
How do I fix CVE-2025-22459?
To mitigate CVE-2025-22459, upgrade Ivanti Endpoint Manager to version 2024 SU1 or version 2022 SU7 or higher.
What does CVE-2025-22459 affect?
CVE-2025-22459 affects Ivanti Endpoint Manager versions prior to 2024 SU1 and 2022 SU7, allowing traffic interception.
Who is impacted by CVE-2025-22459?
Organizations using affected versions of Ivanti Endpoint Manager are at risk of remote unauthenticated attacks.
Can CVE-2025-22459 be exploited remotely?
Yes, CVE-2025-22459 can be exploited by remote unauthenticated attackers to intercept secure communications.