Latest Ivanti Neurons for ITSM vulnerabilities #
Ivanti has issued an advisory disclosing a vulnerability in its Ivanti Neurons for ITSM product, in its on-premises version. Successful exploitation of this vulnerability would allow a remote, unauthenticated attacker to bypass authentication and gain administrative access to a vulnerable system.
The vulnerability affects versions 2023.4, 2024.2, and 2024.3 and has been designated CVE-2025-22462. It has a CVSS score of 9.8 (critical).
What is the impact? #
Successfully exploiting this vulnerability would allow a remote, unauthenticated attacker to bypass authentication and gain administrative privileges on the vulnerable system.
Are updates or workarounds available? #
Ivanti has released updates that address these issues and urges all customers to update as quickly as possible.
How to find potentially vulnerable systems with runZero #
From the Services Inventory, use the following query to locate systems running potentially vulnerable software:
product:"Ivanti Neurons" OR (_asset.protocols:http AND protocol:http AND http.body:"ivanti-neurons-logo")