Ivanti Neurons for ITSM
cpe:2.3:a:ivanti:neurons_for_itsm:*:*:*:*:*:*:*
- 2023.4
- 2024.2
- 2024.3
A vulnerability allowing authentication bypass has been identified in Ivanti Neurons for ITSM (on-premises only) versions 2023.4, 2024.2, and 2024.3 prior to the May 2025 Security Patch. This vulnerability allows remote, unauthenticated attackers to gain administrative access to the system.
Exploitation of this vulnerability could lead to unauthorized administrative access on the affected system.
Users can upgrade to Ivanti Neurons for ITSM versions 2023.4, 2024.2, or 2024.3, all of which include the May 2025 Security Patch. The patch is available for download through the Ivanti License System (ILS).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.