Absolute Path Traversal in Ivanti Endpoint Manager
CVE-2024-13160
Key Information:
- Vendor
Ivanti
- Status
- Vendor
- CVE Published:
- 14 January 2025
Badges
What is CVE-2024-13160?
An absolute path traversal vulnerability exists in Ivanti Endpoint Manager versions prior to the January 2025 Security Update. This allows a remote unauthenticated attacker to exploit the flaw, gaining access to sensitive information stored on the server. Attackers can leverage this vulnerability to traverse the file system and expose critical data, leading to potential compromises of sensitive information.
CISA has reported CVE-2024-13160
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-13160 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Endpoint Manager 2024 January-2025 Security Update
Endpoint Manager 2024 January-2025 Security Update
Endpoint Manager 2022 SU6 January-2025 Security Update
References
EPSS Score
93% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published