SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-8558

Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the…

LOW 2.3EPSS 0.59%

Does this matter?

Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.

Description

Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality.

CVSS 4.0
2.3 LOWCVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.59% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
proofpoint/insider threat management server
Source
security@proofpoint.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.