First published: Tue May 13 2025(Updated: )
An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.
Credit: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Neurons for ITSM | <2023.4 | |
Ivanti Neurons for ITSM | <2024.2 | |
Ivanti Neurons for ITSM | <2024.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22462 is considered a critical vulnerability due to its potential for remote unauthorized administrative access.
CVE-2025-22462 affects on-premises versions of Ivanti Neurons for ITSM prior to 2023.4, 2024.2, and 2024.3.
To fix CVE-2025-22462, apply the May 2025 Security Patch provided by Ivanti for affected versions.
CVE-2025-22462 allows a remote unauthenticated attacker to bypass authentication and gain administrative access.
CVE-2025-22462 is a remote vulnerability, allowing attackers to exploit it without physical access to the system.