Junglewise Threat Intelligence

CVE-2024-13159: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

CVE-2024-13159 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-03-10

Technologies: Ivanti Endpoint Manager (EPM). Vendors: Ivanti.

Executive brief

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability (CWE-36). A remote, unauthenticated attacker can exploit this flaw to access sensitive information or potentially achieve full system compromise.

Affected products

  • Ivanti Endpoint Manager (EPM) Before 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update

Timeline

  • 2025-01-14: disclosed: Initial CVE publication and vendor advisory release
  • 2025-03-10: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2025-03-10: exploited: Confirmed as exploited in the wild per CISA KEV entry

Related threats