Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality.
History

Fri, 07 Nov 2025 02:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:proofpoint:insider_threat_management_server:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Proofpoint
Proofpoint insider Threat Management Server
Vendors & Products Proofpoint
Proofpoint insider Threat Management Server

Mon, 03 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Nov 2025 18:45:00 +0000

Type Values Removed Values Added
Description Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality.
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Proofpoint

Published: 2025-11-03T18:40:03.946Z

Updated: 2025-11-03T19:03:11.645Z

Reserved: 2025-08-04T17:18:04.142Z

Link: CVE-2025-8558

cve-icon Vulnrichment

Updated: 2025-11-03T19:03:07.693Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-03T19:16:16.227

Modified: 2025-11-07T01:49:02.677

Link: CVE-2025-8558

cve-icon Redhat

No data.