CVE-2024-13158: Path Traversal
An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13158?
CVE-2024-13158 is rated as a high severity vulnerability allowing remote code execution.
Who is affected by CVE-2024-13158?
CVE-2024-13158 affects users of Ivanti Endpoint Manager prior to the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update.
How do I fix CVE-2024-13158?
To fix CVE-2024-13158, upgrade to the 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update.
What type of attack does CVE-2024-13158 enable?
CVE-2024-13158 enables a remote authenticated attacker to achieve remote code execution.
What are the prerequisites for exploiting CVE-2024-13158?
An attacker must have remote authenticated admin privileges to exploit CVE-2024-13158.