Ivanti Issues Urgent Fix for High-Risk ITSM Security Gap Allowing Remote Admin Breach
Ivanti has rolled out critical security patches to fix a high-severity vulnerability in its Neurons for ITSM platform. This flaw, which bypasses authentication controls, could let attackers remotely seize full administrative privileges on unprotected systems—no credentials needed.
First detailed on May 13, 2025, the flaw—tracked as CVE-2025-22462—applies only to on-premises deployments and has been rated 9.8 on the CVSS scale, underscoring its serious nature. The impacted versions include Neurons for ITSM 2023.4, 2024.2, 2024.3, and prior releases.
If exploited, the vulnerability opens the door for remote adversaries to gain deep system control. However, exposure depends heavily on how each environment is configured.
Ivanti emphasized that environments with IIS access tightly restricted to specific IPs or domains, or those using a DMZ setup for external access, face significantly lower risk.
Tailored patches for each affected release are now available via Ivanti’s official download portal. Customers are urged to apply these updates immediately to safeguard their systems against potential exploitation.
Security Patch Details – Ivanti Neurons for ITSM (On-Premises Only)
| Product | Impacted Version(s) | Fixed In | Patch Status |
|---|---|---|---|
| Ivanti Neurons for ITSM (On-Prem) | 2023.4 | May 2025 Security Patch for 2023.4 | Available via Ivanti ILS Portal |
| Ivanti Neurons for ITSM (On-Prem) | 2024.2 | May 2025 Security Patch for 2024.2 | Available via Ivanti ILS Portal |
| Ivanti Neurons for ITSM (On-Prem) | 2024.3 | May 2025 Security Patch for 2024.3 | Available via Ivanti ILS Portal |
Ivanti Reframes Risk Profile Amid Critical ITSM Flaw—Urges Swift Action
Although the flaw in Ivanti Neurons for ITSM carries a critical base CVSS rating of 9.8, Ivanti has clarified that the real-world impact may be significantly reduced in hardened environments. Specifically, systems configured with access controls—such as network segmentation and privilege restrictions—fall into a lower-risk bracket, with an adjusted environmental score of 6.9 (Medium).
This distinction underscores the importance of proactive infrastructure design. In instances where access to the ITSM interface is strictly limited to administrative users within protected network zones, the threat level drops substantially.
Ivanti confirmed that no active exploitation has been detected in customer environments as of the public disclosure. The vulnerability was responsibly reported through Ivanti’s coordinated disclosure channel.
This latest security advisory follows a series of high-profile vulnerabilities disclosed by Ivanti in recent months. In April 2025, a critical flaw in Ivanti’s Connect Secure VPN—tracked as CVE-2025-22457—was linked to active exploitation by sophisticated state-aligned actors. Just weeks prior, in March, urgent patches were released to address command execution risks in both Standalone Sentry and Neurons for ITSM.
Organizations running vulnerable versions of Neurons for ITSM are strongly urged to apply the newly released security updates without delay. For environments where immediate patching isn’t feasible, Ivanti recommends reinforcing perimeter defenses—specifically by:
- Locking down the IIS web interface to specific IPs or domain names
- Ensuring external access routes are protected via a DMZ
- Restricting exposure to high-privilege user groups only
These measures, while not a substitute for patching, can significantly lower the attack surface until permanent remediation is applied.




