Back

MEDIUM

IP Spoofing in CyberArk Endpoint Privilege Manager

Published Feb 28, 2025

Description

The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For" header. Thus, the action logging mechanism in the application loses accountability

This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Feb 28, 2025
Updated Mar 5, 2025
Reserved Jan 2, 2025
CISA Vulnrichment
Updated Feb 28, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner CERT-PL
Published Feb 28, 2025
Updated Mar 5, 2025
Exploited since n/a
EUVD-2025-5966