CVE-2025-22463: High severity Ivanti Workspace Control vulnerability
Published Jun 10, 2025
·Updated
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.
Affected Software
2 affected components
Ivanti Workspace Control<10.19.10.0
Ivanti Workspace Control<10.19.10.0
Event History
Jun 10, 2025
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·03:22 PM
News Published
via BleepingComputer·03:23 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-22463?
CVE-2025-22463 is classified as a critical vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2025-22463?
To fix CVE-2025-22463, upgrade Ivanti Workspace Control to version 10.19.10.0 or later to eliminate the hardcoded key.
3
Who is affected by CVE-2025-22463?
CVE-2025-22463 affects users of Ivanti Workspace Control versions prior to 10.19.10.0.
4
What does CVE-2025-22463 allow an attacker to do?
CVE-2025-22463 allows a local authenticated attacker to decrypt the stored environment password, leading to unauthorized access.
5
When was CVE-2025-22463 disclosed?
CVE-2025-22463 was disclosed in 2025 as part of a series of vulnerabilities impacting Ivanti Workspace Control.