CVE-2024-13160: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
Other sources
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Manager (EPM)to a version that resolves this vulnerability.Patch 2024 January-2025 Security Update - Upgrade
Upgrade
Ivanti Endpoint Manager (EPM)to a version that resolves this vulnerability.Patch 2022 SU6 January-2025 Security Update - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-13160?
CVE-2024-13160 is considered a high severity vulnerability due to its potential for remote unauthenticated attackers to leak sensitive information.
How do I fix CVE-2024-13160?
To fix CVE-2024-13160, users should apply the January 2025 Security Update for Ivanti EPM or the 2022 SU6 January 2025 Security Update.
Who is affected by CVE-2024-13160?
CVE-2024-13160 affects users of Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update and the 2022 SU6 January 2025 Security Update.
What kind of information can be leaked due to CVE-2024-13160?
CVE-2024-13160 can allow remote attackers to leak sensitive information stored on the affected systems.
Is authentication required to exploit CVE-2024-13160?
No, CVE-2024-13160 can be exploited by remote unauthenticated attackers without needing any form of authentication.