Critical absolute path traversal vulnerability in Ivanti Endpoint Manager allowing remote unauthenticated attackers to leak sensitive information. The vulnerability has a CVSS score of 9.8 and is actively being exploited in the wild according to CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-01-14
Added to CISA KEV: 2025-03-10 55 DAYS BETWEEN CVE AND KEV
CVE-2024-13161 is a critical security vulnerability affecting Ivanti Endpoint Manager (EPM) [3]. Below is a summary of the known details regarding this vulnerability.
A vulnerability in Ivanti Endpoint Manager (EPM) allows an unauthenticated attacker to coerce the EPM machine account credential via the GetHashForSingleFile ...
Ivanti has released updates addressing critical vulnerabilities (CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161) in Ivanti Endpoint Manager ...
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated ... Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only onβ¦
Vulnerability Details ; CVE-2024-13159. Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January- ...
Summary Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.