Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Nov 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:proofpoint:insider_threat_management_server:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Proofpoint
Proofpoint insider Threat Management Server |
|
| Vendors & Products |
Proofpoint
Proofpoint insider Threat Management Server |
Mon, 03 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Proofpoint
Published: 2025-11-03T18:40:03.946Z
Updated: 2025-11-03T19:03:11.645Z
Reserved: 2025-08-04T17:18:04.142Z
Link: CVE-2025-8558
Updated: 2025-11-03T19:03:07.693Z
Status : Analyzed
Published: 2025-11-03T19:16:16.227
Modified: 2025-11-07T01:49:02.677
Link: CVE-2025-8558
No data.