An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.
| Software | From | Fixed in |
|---|---|---|
| ivanti / neurons_for_itsm | - | 2023.4 |
| ivanti / neurons_for_itsm | 2023.4 | 2023.4.x |
| ivanti / neurons_for_itsm | 2024.2 | 2024.2.x |
| ivanti / neurons_for_itsm | 2024.3 | 2024.3.x |