First published: Tue Jan 14 2025(Updated: )
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
Credit: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager (EPM) | <2024 January-2025 Security Update<2022 SU6 January-2025 Security Update |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10811 is classified with a high severity due to its potential to expose sensitive information.
To remediate CVE-2024-10811, update Ivanti EPM to a version released after the January 2024 Security Update.
CVE-2024-10811 is an absolute path traversal vulnerability that allows unauthorized access to sensitive data.
Organizations using Ivanti Endpoint Manager versions prior to the January 2024 Security Update and 2022 SU6 January-2025 Security Update are affected by CVE-2024-10811.
Yes, CVE-2024-10811 can be exploited remotely by unauthenticated attackers.