Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality.
                
            Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Mon, 03 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Mon, 03 Nov 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality. | |
| Weaknesses | CWE-306 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: Proofpoint
Published:
Updated: 2025-11-03T19:03:11.645Z
Reserved: 2025-08-04T17:18:04.142Z
Link: CVE-2025-8558
Updated: 2025-11-03T19:03:07.693Z
Status : Received
Published: 2025-11-03T19:16:16.227
Modified: 2025-11-03T19:16:16.227
Link: CVE-2025-8558
No data.
                        OpenCVE Enrichment
                    No data.