ZeroHour

CVE-2024-13160

KEV PoC large

Unauthenticated Absolute Path Traversal in Ivanti Endpoint Manager (EPM)

CISA: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
91%p100
Published
()
KEV added
AI analysis

CVE-2024-13160 is an absolute path traversal flaw (CWE-36) in Ivanti Endpoint Manager (EPM) that lets a remote, unauthenticated attacker use attacker-supplied absolute paths to bypass intended path restrictions and read files on the EPM server. It is triggered over the network by sending crafted requests containing absolute paths to the vulnerable EPM component, with no credentials, privileges, or user interaction required. Successful exploitation yields sensitive information disclosure (high confidentiality impact only), such as server files and configuration or credential material, with no direct integrity or availability impact. Any organization running EPM 2024 or EPM 2022 SU6 without the January 2025 security updates is affected. The flaw is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-10 — it carries an EPSS score of 91.2% (top percentile), and a public PoC is available.

What to do: Upgrade EPM to the January 2025 security updates — the '2024 January-2025 Security Update' for the EPM 2024 branch and the '2022 SU6 January-2025 Security Update' for the EPM 2022 SU6 branch — following vendor instructions and applicable BOD 22-01 requirements for federal agencies. Because exploitation is confirmed in the wild, treat internet-exposed or broadly reachable EPM servers as potentially compromised: review access logs and vendor indicators of compromise, and restrict network access to EPM web components until patched.

Affected
Ivanti Endpoint Manager (EPM) 2024all versions before the 2024 January-2025 Security Update
Ivanti Endpoint Manager (EPM) 2022 SU6all versions before the 2022 SU6 January-2025 Security Update
Estimated exposure
large≈ tens of thousands of on-premises EPM deployments worldwide (exact install-base and internet-exposure counts unpublished) — No public install-base or scan-based exposure counts were provided in the data; the order of magnitude is inferred from EPM's status as a widely deployed on-premises enterprise endpoint-management platform (typically one or more core…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CISA Known Exploited Vulnerability
Affected
Ivanti Endpoint Manager (EPM)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
endpoint manager
Weakness
CWE-36
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news