CVE-2024-13161
KEV PoC largeUnauthenticated Absolute Path Traversal in Ivanti Endpoint Manager (EPM)
CISA: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVE-2024-13161 is an absolute path traversal flaw (CWE-36) in Ivanti Endpoint Manager (EPM), scored 7.5 (High) in CVSS 3.1, that allows a remote, unauthenticated attacker to leak sensitive information from the server. An attacker triggers it by sending crafted network requests that supply absolute file paths to the vulnerable EPM service, bypassing path restrictions to read arbitrary files, with high confidentiality impact and no integrity or availability impact per the CVSS vector. All organizations running Ivanti EPM installations that predate the 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update are affected. Exploitation is confirmed: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-03-10 (ransomware use unknown), EPSS assigns a 90.1% probability of exploitation within 30 days (100th percentile), and a public PoC has been published by Horizon3.ai as part of research on related Ivanti EPM credential-coercion flaws (CVE-2024-13159). Given the KEV listing and near-certain near-term exploitation, unpatched EPM servers with any network reachability should be treated as at immediate risk.
What to do: Apply Ivanti's January-2025 Security Updates immediately: upgrade EPM 2024 installations to the 2024 January-2025 Security Update and EPM 2022 SU6 installations to the 2022 SU6 January-2025 Security Update. Because the flaw is in CISA's KEV catalog, federal agencies must patch within the BOD 22-01 deadline, and all organizations should prioritize it; until patched, limit network exposure of EPM core services and review EPM server logs for signs of path-traversal probing or unexpected file reads. When patching, also review Ivanti's advisory for the related EPM vulnerabilities disclosed at the same time (e.g., CVE-2024-13159), since they affect the same servers and fixes ship in the same January-2025 updates.
| Ivanti Endpoint Manager (EPM) 2024 | All versions before the 2024 January-2025 Security Update |
| Ivanti Endpoint Manager (EPM) 2022 SU6 | All versions before the 2022 SU6 January-2025 Security Update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- Affected
- Ivanti Endpoint Manager (EPM)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-36
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N