CVE-2025-6996 Details
Description
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
A vulnerability exists in the agent of Ivanti Endpoint Manager in versions prior to 2024 SU3 and 2022 SU8 Security Update 1. This vulnerability stems from improper encryption practices, which enable a local authenticated attacker to decrypt passwords of other users.
Users can upgrade to Ivanti Endpoint Manager 2024 SU3 or 2022 SU8 Security Update 1. The update is available through the Ivanti License System.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-July-2025-for-Ivanti-EPM-2024-SU2-and-EPM-2022-SU8 | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-257 | Storing Passwords in a Recoverable Format | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | < 2022 2022 - 2022 su1 2022 su2 2022 su3 2022 su4 2022 su5 2022 su6 2022 su7 2022 su8 2024 - 2024 su1 2024 su2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2025 | Initial Analysis | [email protected] |
| Jul 8, 2025 | New CVE Received | ivanti |