CVE Vulnerabilities

CVE-2025-22462

Authentication Bypass Using an Alternate Path or Channel

Published: May 13, 2025 | Modified: Jul 16, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Neurons_for_itsm Ivanti * 2023.4 (excluding)
Neurons_for_itsm Ivanti 2023.4 (including) 2023.4 (including)
Neurons_for_itsm Ivanti 2024.2 (including) 2024.2 (including)
Neurons_for_itsm Ivanti 2024.3 (including) 2024.3 (including)

Potential Mitigations

References