Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-22462


An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.


Published

2025-05-13T16:15:28.530

Last Modified

2025-07-16T18:32:09.720

Status

Analyzed

Source

3c1d8aa1-5a33-4ea4-8992-aadd6440af75

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-288

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti neurons_for_itsm < 2023.4 Yes
Application ivanti neurons_for_itsm 2023.4 Yes
Application ivanti neurons_for_itsm 2024.2 Yes
Application ivanti neurons_for_itsm 2024.3 Yes

References