# Ivanti Neurons for ITSM Patches CVE-2024-45504 and CVE-2024-45505

> Ivanti addresses two high-severity flaws in Neurons for ITSM, CVE-2024-45504 and CVE-2024-45505, preventing session persistence and cross-user data exposure.

- Published: 2026-04-15T12:31:03.000Z
- Severity: high
- Category: Vulnerabilities
- Tags: Ivanti, ITSM, CVE-2024-45504, CVE-2024-45505, Authentication Bypass, Access Control
- Author: Runtime Rebel Intel
- Primary source: https://www.securityweek.com/two-vulnerabilities-patched-in-ivanti-neurons-for-itsm/
- Canonical: https://runtimerebel.com/blog/ivanti-neurons-for-itsm-patches-cve-2024-45504-and-cve-2024-45505

## Key points

- Immediate impact: Attackers can maintain persistent access via disabled accounts or harvest sensitive information from other active user sessions within the ITSM environment.
- Affected systems: These vulnerabilities affect all Ivanti Neurons for ITSM versions prior to 2023.4, impacting both cloud and on-premises deployments.
- Remediation: Administrators should upgrade to version 2024.1 or apply the relevant security hotfixes provided by Ivanti immediately.

Ivanti has released security updates for its Neurons for ITSM (IT Service Management) platform to address two high-severity vulnerabilities. These flaws could potentially allow unauthorized persistence and data exposure, highlighting a significant risk to organizations relying on Ivanti for automated service desk operations. According to [SecurityWeek](https://www.securityweek.com/two-vulnerabilities-patched-in-ivanti-neurons-for-itsm/), the vulnerabilities impact both cloud and on-premises deployments, necessitating urgent attention from security administrators.

## Overview of Ivanti Neurons for ITSM Security Risks
The [CVE](/glossary#cve) vulnerabilities identified involve improper authentication management and flawed access controls. While Ivanti has been a frequent target for [APT](/glossary#apt) groups in recent months, there is currently no evidence of these specific vulnerabilities being exploited in the wild as [Zero-Day](/glossary#zero-day) threats. However, given the criticality of ITSM systems—which often hold extensive data on internal infrastructure, user identities, and system configurations—the potential for exploitation is high.

Organizations use Ivanti Neurons for ITSM to streamline help desk workflows and asset management. Because these systems often integrate deeply with active directory and internal ticketing, a compromise here can facilitate [Lateral Movement](/glossary#lateral-movement) or serve as a jumping-off point for broader network infiltration. The [CVSS](/glossary#cvss) scores for these issues reflect the high impact on confidentiality and integrity.

## Technical Analysis: CVE-2024-45504 and CVE-2024-45505

### Ivanti Neurons for ITSM authentication bypass vulnerability
The first vulnerability, [CVE-2024-45504](https://nvd.nist.gov/vuln/detail/CVE-2024-45504), has a [CVSS](/glossary#cvss) score of 8.1. It is characterized as an "Improper Restriction of Excessive Authentication Attempts" flaw. In a standard security model, once a user account is disabled, all active sessions and subsequent login attempts should be invalidated. However, this vulnerability allows a remote attacker who has already gained access to maintain that access even after their account has been officially disabled.

This effectively acts as a persistence mechanism. If a [SOC](/glossary#soc) identifies a compromised account and disables it, the attacker could theoretically remain within the environment if the patch has not been applied. This undermines the standard incident response procedure of account revocation and highlights why understanding **how to patch CVE-2024-45504 and CVE-2024-45505** is essential for maintaining a [Zero Trust](/glossary#zero-trust) architecture.

### Exploiting Improper Access Control in ITSM Environments
The second vulnerability, [CVE-2024-45505](https://nvd.nist.gov/vuln/detail/CVE-2024-45505), carries a [CVSS](/glossary#cvss) score of 7.1. This is an "Improper Access Control" issue. It allows an authenticated remote attacker to access information belonging to other user sessions. While the attacker must already be authenticated to the system, the ability to access data between sessions allows for significant information disclosure.

In practice, an attacker could harvest session tokens, personal identifiable information (PII), or technical metadata about the infrastructure that they are not authorized to view. This type of flaw is particularly dangerous in multi-tenant environments or large enterprises where different departments might have segregated data within the same ITSM instance.

## Impact and Exploitation Scenarios
The lack of proper session isolation means that an attacker with low-level privileges could achieve [Privilege Escalation](/glossary#privilege-escalation) by capturing data from higher-privileged users. If an administrator is logged into the system at the same time as an attacker, the attacker might leverage CVE-2024-45505 to extract administrative session data.

Furthermore, the **Ivanti Neurons for ITSM version 2023.4 security update** is critical because the persistence provided by CVE-2024-45504 allows attackers to survive eviction attempts. Traditional [EDR](/glossary#edr) solutions might monitor for suspicious processes on the host, but if the attacker's presence is rooted in a legitimate but "undead" web session within the ITSM platform, detection becomes significantly more difficult without specific [SIEM](/glossary#siem) logging for application-level session activity.

## Mitigation and Patch Guidance
Ivanti has confirmed that these vulnerabilities affect version 2023.4, 2023.3, and all earlier versions of the Neurons for ITSM platform. To secure the environment, defenders must prioritize the upgrade to version 2024.1. For organizations unable to perform a full version upgrade immediately, Ivanti has provided specific hotfixes.

Defenders should verify their current versioning and ensure that the **Ivanti Neurons for ITSM authentication bypass vulnerability** is mitigated by applying the following steps:

*   Audit all active sessions and force a global logout after patching to ensure any existing sessions are re-authenticated.
*   Review audit logs for unusual access patterns, particularly from accounts that were recently disabled or scheduled for decommissioning.
*   Implement strict session timeouts and multi-factor authentication to add layers of defense against session-based exploits.

By addressing these flaws, organizations can prevent unauthorized persistence and protect the sensitive operational data contained within their ITSM platforms.

**Related:** [Ivanti vTM Authentication Bypass: CVE-2024-7593 Mitigation Guide](/blog/ivanti-vtm-authentication-bypass-cve-2024-7593-mitigation-guide), [Ivanti Connect Secure RCE via CVE-2024-21887 — Mitigation Guide](/blog/ivanti-connect-secure-rce-via-cve-2024-21887-mitigation-guide)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/ivanti-neurons-for-itsm-patches-cve-2024-45504-and-cve-2024-45505
