CVE-2025-22460: High severity ivanti cloud services application vulnerability
Published May 13, 2025
·Updated
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
Affected Software
2 affected components
Ivanti Cloud Services Application<5.0.5
Ivanti Cloud Services Appliance<5.0.5
Event History
May 13, 2025
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·03:54 PM
News Published
via BleepingComputer·03:56 PM
News Published
via BleepingComputer·06:26 PM
Known Exploited
06:27 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-22460?
CVE-2025-22460 has been rated as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2025-22460?
To fix CVE-2025-22460, upgrade the Ivanti Cloud Services Application to version 5.0.5 or later.
3
Who is affected by CVE-2025-22460?
All users of Ivanti Cloud Services Application versions prior to 5.0.5 are affected by CVE-2025-22460.
4
What type of attack does CVE-2025-22460 allow?
CVE-2025-22460 allows a local authenticated attacker to escalate their privileges within the affected application.
5
When was CVE-2025-22460 announced?
CVE-2025-22460 was announced as a security advisory affecting Ivanti Cloud Services Application.