CVE-2025-6996: Improper Encryption in Ivanti Endpoint Manager
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Managerto a version that resolves this vulnerability.Fixed in 2024 SU3 - Upgrade
Upgrade
Ivanti Endpoint Managerto a version that resolves this vulnerability.Fixed in 2022 SU8 Security Update 1 - Operational
Because versions prior to 2024 SU3 / 2022 SU8 Security Update 1 may allow decryption of other users’ passwords by a local authenticated attacker, rotate any affected user passwords after upgrading to the fixed security updates.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6996?
CVE-2025-6996 has been rated as a high severity vulnerability due to the potential for local authenticated attackers to decrypt other users' passwords.
How do I fix CVE-2025-6996?
To mitigate CVE-2025-6996, upgrade Ivanti Endpoint Manager to version 2024 SU3 or 2022 SU8 Security Update 1.
What types of attack can CVE-2025-6996 facilitate?
CVE-2025-6996 enables a local authenticated attacker to decrypt passwords of other users, which could lead to unauthorized access.
What versions of Ivanti Endpoint Manager are affected by CVE-2025-6996?
CVE-2025-6996 affects Ivanti Endpoint Manager versions prior to 2024 SU3 and 2022 SU8 Security Update 1.
Is remote access necessary for CVE-2025-6996 exploitation?
No, CVE-2025-6996 can be exploited by local authenticated attackers, so physical access to the system is not required.