SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Ivanti EPM Under Fire: How Attackers Can Steal Credentials and Access Your Data

Ivanti EPM Under Fire: How Attackers Can Steal Credentials and Access Your Data

Ivanti has recently addressed three high-severity vulnerabilities in its Endpoint Manager (EPM) software. These flaws could allow attackers to decrypt other users’ passwords or access sensitive database information if exploited. This blog post provides a detailed overview of these vulnerabilities an...

Jul 8, 2025By Meghana Raatni4 min read

Ivanti has recently addressed three high-severity vulnerabilities in its Endpoint Manager (EPM) software. These flaws could allow attackers to decrypt other users’ passwords or access sensitive database information if exploited. This blog post provides a detailed overview of these vulnerabilities and the necessary steps to mitigate potential risks for organizations relying on Ivanti EPM.

Vulnerability Overview

The recent security update from Ivanti targets three specific vulnerabilities, each with a high severity rating according to the Common Vulnerability Scoring System (CVSS).

  • CVE-2025-6995 & CVE-2025-6996: Improper Encryption – These vulnerabilities stem from improper use of encryption in the EPM agent. Both carry a CVSS score of 8.4 (High) and could enable a local authenticated attacker to decrypt other users’ passwords.
  • CVE-2025-7037: SQL Injection – This vulnerability involves an SQL injection flaw with a CVSS score of 7.2 (High), allowing a remote authenticated attacker with admin privileges to read arbitrary data from the database.

A detailed breakdown of the vulnerabilities is presented below:

Affected Versions and Solutions

These vulnerabilities affect Ivanti Endpoint Manager versions before 2024 SU3 and 2022 SU8 Security Update 1. The encryption flaws specifically target the agent component, making local access a potential gateway for attackers to compromise user credentials.

The affected versions and corresponding resolved versions are:

Organizations using affected versions are strongly advised to update immediately to the resolved versions – 2024 SU3 or 2022 SU8 Security Update 1.

TTP Analysis

The vulnerabilities in Ivanti Endpoint Manager allow attackers to perform various malicious activities:

  • T1081 – Credentials in Files: CVE-2025-6995 and CVE-2025-6996 enable local attackers to decrypt user passwords, potentially gaining unauthorized access to user accounts.
  • T1005 – Data from Local System: CVE-2025-7037 allows remote attackers with administrative privileges to perform SQL injection attacks, potentially exfiltrating sensitive data from the database.

These vulnerabilities highlight the importance of securing endpoint management tools and following the principle of least privilege to prevent unauthorized access and data breaches. The tactics used by attackers align with gaining unauthorized access to credentials and exfiltrating valuable data from the compromised system. These tactics fall under TA0006 – Credential Access and TA0009 – Collection tactics.

Mitigation and Recommendations

Ivanti has emphasized that there is no evidence of actively exploiting these vulnerabilities before their disclosure. The issues were reported through the company’s responsible disclosure program, ensuring timely patches before any known attacks. To mitigate the risks, organizations should take the following actions:

  • Immediate Updates: Without delay, apply the necessary updates to the resolved versions (2024 SU3 or 2022 SU8 Security Update 1).
  • System Audits: IT administrators should audit their systems for affected versions of Ivanti Endpoint Manager.
  • Unusual Activity Monitoring: While no exploitation has been reported, monitor systems for unusual activity as a precaution.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

Ivanti EPM Under Fire: How Attackers Can Steal Credentials and Access | SecPod