CVE-2024-13161
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 31 March 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 90.08% probability · 100th percentile
- CISA KEV
- Listed 10 March 2025 · due 31 March 2025
- Weakness
- CWE-36
- Affected
- ivanti/endpoint manager
- Source
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2024-13161
References
- https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-13161US Government Resource
- https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilities/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.