• News/
  • https://www.bleepingcomputer.com/news/security/cisa-tags-critical-ivanti-epm-flaws-as-actively-exploited-in-attacks/

CISA tags critical Ivanti EPM flaws as actively exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 11, 2025
·
Updated

CISA warned U.S. federal agencies to secure their networks against attacks exploiting three critical vulnerabilities affecting Ivanti Endpoint Manager (EPM) appliances. The three flaws (CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161) are due to absolute path traversal weaknesses that can let remote unauthenticated attackers fully compromise vulnerable servers. They were reported in October by Horizon3.ai vulnerability researcher Zach Hanley and patched by Ivanti on January 13. Just over a month later, Horizon3.ai also released proof-of-concept exploits that can be used in relay attacks for unauthenticated coercion of the Ivanti EPM machine credentials. On Monday, CISA added the three vulnerabilities to its Known Exploited Vulnerabilities catalog, which lists security flaws the cybersecurity agency has marked as exploited in the wild. Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until March 31, to secure their systems against ongoing attacks, as mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise." CISA said. "Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice." Ivanti has not yet updated i...

Read full article

Affected Software

4 affected components
Ivanti Endpoint Manager
Ivanti Cloud Service Appliances
Ivanti Connect Secure VPN
Ivanti Endpoint Manager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA's warning about critical vulnerabilities in Ivanti Endpoint Manager and related products that are actively being exploited.

2

What security implications are discussed?

The article highlights the need for U.S. federal agencies to secure their networks against attacks that exploit these vulnerabilities.

3

What specific vulnerabilities are mentioned in the article?

The vulnerabilities mentioned are CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161.

4

Which Ivanti products are affected by these vulnerabilities?

The affected products include Ivanti Endpoint Manager, Ivanti Cloud Service Appliances, and Ivanti Connect Secure VPN.

5

What actions should organizations take in response to this article?

Organizations should immediately assess their systems for the listed vulnerabilities and apply any patches or mitigations released by Ivanti.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203