Description
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read in the Agent component of Ivanti Endpoint Manager can be triggered by a remote, unauthenticated attacker, causing the agent service to crash. The flaw does not provide direct code execution; instead, it leads to a loss of availability for the protected endpoint.

Affected Systems

Ivanti Endpoint Manager, specifically versions released before 2024 SU7. Any deployment using an Agent that has not been upgraded to at least the 2024 SU7 release is susceptible.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. No EPSS score is available, so current exploitation likelihood is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers need only remote communication with the agent service, making it a likely remote threat vector that can induce service downtime without additional privileges.

Generated by OpenCVE AI on August 11, 2026 at 23:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ivanti Endpoint Manager Agent to version 2024 SU7 or later, which contains the security fix for the out-of-bounds read.
  • Limit inbound traffic to the Agent service by configuring firewall rules to allow connections only from trusted networks.
  • If a patch cannot be applied immediately, isolate the agent process in a separate container or virtual machine and monitor it for crashes, restarting it automatically to maintain availability.

Generated by OpenCVE AI on August 11, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti endpoint Manager
Vendors & Products Ivanti
Ivanti endpoint Manager

Tue, 11 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Ivanti Endpoint Manager Agent Enables Remote Crash

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ivanti Endpoint Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-08-11T14:49:47.297Z

Reserved: 2026-07-28T18:10:05.804Z

Link: CVE-2026-18125

cve-icon Vulnrichment

Updated: 2026-08-11T14:49:43.986Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T15:17:28.053

Modified: 2026-08-31T19:27:23.020

Link: CVE-2026-18125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:30:05Z

Weaknesses