CVE-2024-13161: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
Other sources
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of Ivanti Endpoint Manager if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-13161?
CVE-2024-13161 is rated as a high-severity vulnerability that allows remote unauthenticated attackers to exploit sensitive information.
How do I fix CVE-2024-13161?
To mitigate CVE-2024-13161, users should upgrade to the January-2024 Security Update or the January-2025 Security Update for Ivanti EPM.
What type of attack does CVE-2024-13161 involve?
CVE-2024-13161 involves an absolute path traversal attack which can lead to information leakage.
Who is affected by CVE-2024-13161?
CVE-2024-13161 affects users of Ivanti Endpoint Manager versions prior to the January-2024 and January-2025 Security Updates.
Can CVE-2024-13161 be exploited remotely?
Yes, CVE-2024-13161 can be exploited remotely by unauthenticated attackers.