CVE-2024-13161: critical vulnerability in Ivanti Endpoint Manager
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A security flaw in Ivanti EPM allows attackers to access files anywhere on the server by using specially crafted file paths, potentially exposing sensitive company data without needing to log in.
Absolute path traversal vulnerability in Ivanti EPM (pre-2024 January-2025 SU and 2022 SU6 January-2025 SU) enables unauthenticated remote information disclosure through improper path validation. Attack vector is network-based with no authentication required; impact includes unauthorized access to sensitive files and system information.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.