CVE-2024-13160
KEV PoC largeUnauthenticated Absolute Path Traversal in Ivanti Endpoint Manager (EPM)
CISA: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVE-2024-13160 is an absolute path traversal flaw (CWE-36) in Ivanti Endpoint Manager (EPM) that lets a remote, unauthenticated attacker use attacker-supplied absolute paths to bypass intended path restrictions and read files on the EPM server. It is triggered over the network by sending crafted requests containing absolute paths to the vulnerable EPM component, with no credentials, privileges, or user interaction required. Successful exploitation yields sensitive information disclosure (high confidentiality impact only), such as server files and configuration or credential material, with no direct integrity or availability impact. Any organization running EPM 2024 or EPM 2022 SU6 without the January 2025 security updates is affected. The flaw is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-10 — it carries an EPSS score of 91.2% (top percentile), and a public PoC is available.
What to do: Upgrade EPM to the January 2025 security updates — the '2024 January-2025 Security Update' for the EPM 2024 branch and the '2022 SU6 January-2025 Security Update' for the EPM 2022 SU6 branch — following vendor instructions and applicable BOD 22-01 requirements for federal agencies. Because exploitation is confirmed in the wild, treat internet-exposed or broadly reachable EPM servers as potentially compromised: review access logs and vendor indicators of compromise, and restrict network access to EPM web components until patched.
| Ivanti Endpoint Manager (EPM) 2024 | all versions before the 2024 January-2025 Security Update |
| Ivanti Endpoint Manager (EPM) 2022 SU6 | all versions before the 2022 SU6 January-2025 Security Update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- Affected
- Ivanti Endpoint Manager (EPM)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-36
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N