CISA warned U.S. federal agencies to secure their networks against attacks exploiting three critical vulnerabilities affecting Ivanti Endpoint Manager (EPM) appliances. The three flaws (CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161) are due to absolute path traversal weaknesses that can let remote unauthenticated attackers fully compromise vulnerable servers. They were reported in October by Horizon3.ai vulnerability researcher Zach Hanley and patched by Ivanti on January 13. Just over a month later, Horizon3.ai also released proof-of-concept exploits that can be used in relay attacks for unauthenticated coercion of the Ivanti EPM machine credentials. On Monday, CISA added the three vulnerabilities to its Known Exploited Vulnerabilities catalog, which lists security flaws the cybersecurity agency has marked as exploited in the wild. Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until March 31, to secure their systems against ongoing attacks, as mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise." CISA said. "Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice." Ivanti has not yet updated i...
CISA tags critical Ivanti EPM flaws as actively exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Mar 11, 2025
·Updated
Affected Software
4 affected components
Ivanti Endpoint Manager
Ivanti Cloud Service Appliances
Ivanti Connect Secure VPN
Ivanti Endpoint Manager
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses CISA's warning about critical vulnerabilities in Ivanti Endpoint Manager and related products that are actively being exploited.
2
What security implications are discussed?
The article highlights the need for U.S. federal agencies to secure their networks against attacks that exploit these vulnerabilities.
3
What specific vulnerabilities are mentioned in the article?
The vulnerabilities mentioned are CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161.
4
Which Ivanti products are affected by these vulnerabilities?
The affected products include Ivanti Endpoint Manager, Ivanti Cloud Service Appliances, and Ivanti Connect Secure VPN.
5
What actions should organizations take in response to this article?
Organizations should immediately assess their systems for the listed vulnerabilities and apply any patches or mitigations released by Ivanti.