Igel develops endpoint and device-management software, including its Universal Management Suite and operating system, that centralizes configuration and control across enterprise thin-client and zero-client environments. Vulnerabilities in this vendor's portfolio cluster around authentication and cryptographic weaknesses—hard-coded credentials, cleartext transmission of sensitive data, improper cryptographic-signature verification, and incorrect default permissions—reflecting the trust and secrets management demands of centralized device administration. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Igel over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47827MEDIUM In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be m | Jun 5, 2025 | 4.6 | 58 | YES | NO |
CVE-2022-25806HIGH An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted s | Jun 9, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-25805MEDIUM An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind credentials by the cmd_mgt_load_mgt_tree command allows an at | Jun 9, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-25804MEDIUM An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HKE | Jun 9, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-25807MEDIUM An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker, who has discovered encrypted | Jun 9, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Igel.
Media articles that mention a CVE ID that affects a product developed by Igel — matched by CVE ID, not by vendor name.