CVE-2025-22462: Critical severity ivanti neurons for itsm vulnerability
An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22462?
CVE-2025-22462 is considered a critical vulnerability due to its potential for remote unauthorized administrative access.
Who is affected by CVE-2025-22462?
CVE-2025-22462 affects on-premises versions of Ivanti Neurons for ITSM prior to 2023.4, 2024.2, and 2024.3.
How do I fix CVE-2025-22462?
To fix CVE-2025-22462, apply the May 2025 Security Patch provided by Ivanti for affected versions.
What type of attack is possible with CVE-2025-22462?
CVE-2025-22462 allows a remote unauthenticated attacker to bypass authentication and gain administrative access.
Is CVE-2025-22462 a local or remote vulnerability?
CVE-2025-22462 is a remote vulnerability, allowing attackers to exploit it without physical access to the system.