Authentication Bypass in Insider Threat Management Server from Proofpoint
CVE-2025-8558
What is CVE-2025-8558?
The Insider Threat Management Server from Proofpoint has a vulnerability that allows unauthenticated users on an adjacent network to bypass authentication. This exploitation enables malicious actors to unregister agents when the number of registered agents exceeds the licensed limit. This results in a denial of service, preventing the server from processing new events from those affected agents, leading to a significant compromise of the system's integrity and availability while confidentiality remains intact.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Insider Threat Management (ITM) Server 0 < 7.17.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
