CVE-2025-22459
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.31%
- CWE
- CWE-296
- Published
- 2025-04-08
- Last modified
- 2026-03-13
Affected products
- Ivanti Endpoint Manager
- Ivanti Endpoint Manager
Weakness type
Related vulnerabilities
- CVE-2026-73542 — Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle...
- CVE-2026-24066 — Slate Digital Connect macOS XPC certificate validation privilege escalation
- CVE-2026-42789 — Non-CA certificate accepted as intermediate issuer in public_key path validation
- CVE-2025-10539 — Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
- CVE-2026-33779 — Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
- CVE-2026-27134 — Strimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autentication
- CVE-2026-27133 — Strimzi All CAs from CA chain will be trusted in Kafka Connect and Kafka MirrorMaker 2 target clusters
- CVE-2025-48057 — Icinga 2 certificate renewal might incorrectly renew an invalid certificate