ZeroHour

CVE-2024-13161

KEV PoC large

Unauthenticated Absolute Path Traversal in Ivanti Endpoint Manager (EPM)

CISA: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
90%p100
Published
()
KEV added
AI analysis

CVE-2024-13161 is an absolute path traversal flaw (CWE-36) in Ivanti Endpoint Manager (EPM), scored 7.5 (High) in CVSS 3.1, that allows a remote, unauthenticated attacker to leak sensitive information from the server. An attacker triggers it by sending crafted network requests that supply absolute file paths to the vulnerable EPM service, bypassing path restrictions to read arbitrary files, with high confidentiality impact and no integrity or availability impact per the CVSS vector. All organizations running Ivanti EPM installations that predate the 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update are affected. Exploitation is confirmed: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-03-10 (ransomware use unknown), EPSS assigns a 90.1% probability of exploitation within 30 days (100th percentile), and a public PoC has been published by Horizon3.ai as part of research on related Ivanti EPM credential-coercion flaws (CVE-2024-13159). Given the KEV listing and near-certain near-term exploitation, unpatched EPM servers with any network reachability should be treated as at immediate risk.

What to do: Apply Ivanti's January-2025 Security Updates immediately: upgrade EPM 2024 installations to the 2024 January-2025 Security Update and EPM 2022 SU6 installations to the 2022 SU6 January-2025 Security Update. Because the flaw is in CISA's KEV catalog, federal agencies must patch within the BOD 22-01 deadline, and all organizations should prioritize it; until patched, limit network exposure of EPM core services and review EPM server logs for signs of path-traversal probing or unexpected file reads. When patching, also review Ivanti's advisory for the related EPM vulnerabilities disclosed at the same time (e.g., CVE-2024-13159), since they affect the same servers and fixes ship in the same January-2025 updates.

Affected
Ivanti Endpoint Manager (EPM) 2024All versions before the 2024 January-2025 Security Update
Ivanti Endpoint Manager (EPM) 2022 SU6All versions before the 2022 SU6 January-2025 Security Update
Estimated exposure
large~10,000-100,000 enterprise EPM deployments (public internet scans typically show thousands of exposed EPM core servers) — Estimated from deployment patterns of Ivanti EPM (formerly LANDESK), a widely deployed enterprise endpoint-management suite with an installed base in the tens of thousands of core-server deployments, where only a few thousand cores are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CISA Known Exploited Vulnerability
Affected
Ivanti Endpoint Manager (EPM)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
endpoint manager
Weakness
CWE-36
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news