Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2022 SU6
- <= 2024
A vulnerability exists in Ivanti Endpoint Manager versions 2022 SU6 and prior, as well as in the 2024 release, due to improper validation of certificates. This flaw enables remote, unauthenticated attackers to intercept limited traffic between clients and servers.
Exploitation of this vulnerability allows for interception of traffic between clients and servers, potentially leading to unauthorized access to sensitive information.
Users can upgrade to Ivanti Endpoint Manager 2022 SU8 or Ivanti Endpoint Manager 2024 SU2. The latest versions are available for download through the Ivanti License System.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.