Junglewise Threat Intelligence

CVE-2024-13161: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

CVE-2024-13161 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-03-10

Technologies: Ivanti Endpoint Manager (EPM). Vendors: Ivanti.

Executive brief

An absolute path traversal vulnerability in Ivanti Endpoint Manager (EPM) allows a remote, unauthenticated attacker to access sensitive information. The flaw exists in versions prior to the January 2025 security updates for EPM 2024 and EPM 2022 SU6.

Affected products

  • Ivanti Endpoint Manager (EPM) Before 2024 January-2025 Security Update; 2022 SU6 before January-2025 Security Update

Timeline

  • 2025-01-14: disclosed: NVD Published Date and initial CVE receipt from Ivanti
  • 2025-03-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-10: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats