An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
This vulnerability is actively exploited in the wild. Immediate patching is strongly recommended.
Due Date: Mar 23, 2026
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days