Impact
Cleartext transmission of user credentials for external SQL connections in Ivanti Endpoint Manager’s Core component exposes sensitive data. A remote attacker who can perform a Man‑in‑the‑Middle attack can capture these credentials during normal operation, enabling potential compromise of the connected databases. The weakness arises from insecure communication that fails to encrypt or otherwise protect the transmission, which is a classic example of CWE‑295.
Affected Systems
The vulnerability affects all releases of Ivanti Endpoint Manager prior to version 2024 SU7. The impact applies regardless of the specific environment, as the flaw is present in the Core module that handles external SQL integration across all unpatched variants.
Risk and Exploitability
The CVSS v3.1 score is 8.1, indicating high severity with a high potential for confidentiality compromise. Although the EPSS score is not available, the lack of a known public exploit and absence from the CISA KEV catalog do not reduce the risk; the flaw still presents a likely vector for credential leakage in environments where network traffic is not secured. The primary attack requires the ability to intercept or modify traffic between the Endpoint Manager server and the external database, so environments that expose these connections without encryption are the most vulnerable. Given the high score and the clear potential for credential theft, remediation should be treated with priority.
OpenCVE Enrichment