« Volver al listado

CVE-2025-22462

Estado: AnalizadaCrítica (9.8)—

An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:N/UI:N indica vulnerabilidad remota sin autenticación previa (T1190). El bypass de autenticación permite acceso administrativo, impactando T1078 (credenciales) y T1068 (escalada a admin).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-22462",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-22462",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-13T19:39:34.075517Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
      "affectedData": [
        {
          "vendor": "Ivanti",
          "product": "Neurons for ITSM (on-prem)",
          "versions": [
            {
              "status": "unaffected",
              "version": "2023.4 w/ May 2025 Security Patch",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "2024.2 w/ May 2025 Security Patch",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "2024.3 w/ May 2025 Security Patch",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-05-13T16:15:28.530",
  "references": [
    {
      "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-on-premises-only-CVE-2025-22462",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
      "description": [
        {
          "lang": "en",
          "value": "CWE-288"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system."
    },
    {
      "lang": "es",
      "value": "Una omisión de autenticación en Ivanti Neurons para ITSM (solo local) anterior a 2023.4, 2024.2 y 2024.3 con el parche de seguridad de mayo de 2025 permite que un atacante remoto no autenticado obtenga acceso administrativo al sistema."
    }
  ],
  "lastModified": "2026-06-17T08:47:32.207",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ivanti:neurons_for_itsm:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75BA7A8E-E2F2-41B3-9BD1-56CFC430887E",
              "versionEndExcluding": "2023.4"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:neurons_for_itsm:2023.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DFAC472-854D-4740-913E-A3DC5A48CD86"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:neurons_for_itsm:2024.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F20362DA-5407-4FEC-B463-061B1F8DA506"
            },
            {
              "criteria": "cpe:2.3:a:ivanti:neurons_for_itsm:2024.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D009CE5-D185-4841-99BA-C8EB086C5F01"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75"
}