Executive brief
An absolute path traversal vulnerability in Ivanti Endpoint Manager (EPM) allows a remote, unauthenticated attacker to access sensitive information. The flaw exists in versions prior to the January 2025 security updates for EPM 2024 and EPM 2022 SU6.
Affected products
- Ivanti Endpoint Manager (EPM) Before 2024 January-2025 Security Update; 2022 SU6 before January-2025 Security Update
Timeline
- 2025-01-14: disclosed: NVD Published Date and initial CVE receipt from Ivanti
- 2025-03-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-10: exploited: Reported as exploited in the wild per CISA KEV entry