CVE-2024-10811: Path Traversal
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-10811?
CVE-2024-10811 is classified with a high severity due to its potential to expose sensitive information.
How do I fix CVE-2024-10811?
To remediate CVE-2024-10811, update Ivanti EPM to a version released after the January 2024 Security Update.
What type of vulnerability is CVE-2024-10811?
CVE-2024-10811 is an absolute path traversal vulnerability that allows unauthorized access to sensitive data.
Who is affected by CVE-2024-10811?
Organizations using Ivanti Endpoint Manager versions prior to the January 2024 Security Update and 2022 SU6 January-2025 Security Update are affected by CVE-2024-10811.
Can CVE-2024-10811 be exploited remotely?
Yes, CVE-2024-10811 can be exploited remotely by unauthenticated attackers.