CVE-2025-6995: Improper Encryption in Ivanti Endpoint Manager
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Manager agentto a version that resolves this vulnerability.Fixed in 2024 SU3 - Upgrade
Upgrade
Ivanti Endpoint Manager agentto a version that resolves this vulnerability.Fixed in 2022 SU8 Security Update 1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6995?
CVE-2025-6995 is classified as a high-severity vulnerability due to its potential to allow local authenticated attackers to decrypt sensitive information.
How do I fix CVE-2025-6995?
To remediate CVE-2025-6995, update your Ivanti Endpoint Manager to version 2024 SU3 or 2022 SU8 Security Update 1 or later.
Who is affected by CVE-2025-6995?
CVE-2025-6995 affects users of Ivanti Endpoint Manager versions prior to 2024 SU3 and 2022 SU8 Security Update 1.
What impact does CVE-2025-6995 have on affected systems?
CVE-2025-6995 allows local authenticated attackers to decrypt other users' passwords, leading to unauthorized access to sensitive data.
Is there a workaround for CVE-2025-6995?
There is no known workaround for CVE-2025-6995, making the upgrade to the secure version the only mitigation.