← Back to CVE List
Vulnerability Intelligence Report

CVE-2025-22460

Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-1392 ↗CWE-1392: Use of Default Credentials

Affected Products & Versions

Vendor Product Affected Versions
Ivanti CSA (Cloud Services Appliance) 5.0.5 (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.326%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityIvanti · Vendor · USA
Reserved2025-01-07T02:19:22
Published2025-05-13T15:09:30
Last Updated2025-05-13T19:43:10

LINK COPIED TO CLIPBOARD