CVE-2024-13160: critical vulnerability in Ivanti Endpoint Manager
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A vulnerability in Ivanti EPM allows attackers to access sensitive files on the server by using absolute file paths, without needing to log in. This puts confidential information at risk.
Absolute path traversal vulnerability in Ivanti EPM (versions before 2024 January-2025 SU and 2022 SU6 January-2025 SU) allows unauthenticated remote attackers to bypass path restrictions and read arbitrary files from the filesystem. The vulnerability enables information disclosure of sensitive data through improper input validation on file path parameters.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.