Privilege Escalation Vulnerability in Ivanti Cloud Services Application
CVE-2025-22460

7.8HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
13 May 2025

What is CVE-2025-22460?

A vulnerability in the Ivanti Cloud Services Application allows local authenticated users to escalate their privileges due to the presence of default credentials. Attackers leveraging this weakness can gain higher access levels, potentially compromising sensitive information and system integrity. It is crucial for organizations using versions prior to 5.0.5 to take immediate action to mitigate risks associated with unauthorized access.

Affected Version(s)

CSA (Cloud Services Appliance) 5.0.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.