CVE-2024-13159: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
Other sources
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Managerto a version that resolves this vulnerability.Patch 2024 January-2025 Security Update - Upgrade
Upgrade
Ivanti Endpoint Managerto a version that resolves this vulnerability.Patch 2022 SU6 January-2025 Security Update - Compensating control
Follow applicable BOD 22-01 guidance for cloud services
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-13159?
The severity of CVE-2024-13159 is considered high due to its ability to allow remote unauthenticated attackers to leak sensitive information.
How do I fix CVE-2024-13159?
To fix CVE-2024-13159, users must upgrade to the Ivanti EPM version released after January 2024 or the January 2022 SU6 Security Update.
What types of attacks can exploit CVE-2024-13159?
CVE-2024-13159 can be exploited through absolute path traversal attacks, enabling attackers to access unauthorized files.
Who is affected by CVE-2024-13159?
Organizations using Ivanti Endpoint Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update are affected by CVE-2024-13159.
What data is at risk with CVE-2024-13159?
CVE-2024-13159 puts sensitive information at risk, as attackers may gain access to system files and configurations through path traversal.