Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2022 SU8
- <= 2024 SU2
A vulnerability exists in the agent of Ivanti Endpoint Manager in versions prior to 2024 SU3 and 2022 SU8 Security Update 1. This vulnerability arises from improper encryption practices, which enable a local authenticated attacker to decrypt passwords of other users.
Exploitation of this vulnerability allows for unauthorized decryption of user passwords, potentially leading to further unauthorized actions or access within the application or system.
Users can upgrade to Ivanti Endpoint Manager 2024 SU3 or 2022 SU8 Security Update 1. The latest versions are available for download through the Ivanti License System.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.