Vulnerability record · CVE-2024-13159 · published 14 January 2025
CVE-2024-13159: Ivanti EPM absolute path traversal leaks sensitive files
Ivanti · Endpoint Manager
Ivanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory. It affects EPM before the 2024 January-2025 Security Update and the 2022 SU6 January-2025 Security Update. Because the endpoint manager holds credentials and configuration for managed devices, leaked files can expose sensitive information at scale.
Description
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with a near-maximum EPSS score, is remotely exploitable without authentication, and exposes sensitive data from a central management server.
What it is
Ivanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory. It affects EPM before the 2024 January-2025 Security Update and the 2022 SU6 January-2025 Security Update. Because the endpoint manager holds credentials and configuration for managed devices, leaked files can expose sensitive information at scale.
Impact
An attacker gains read access to sensitive files on the EPM server, which can include configuration and credential material useful for lateral movement or follow-on compromise. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality only.
Attack surface
Reachable over the network with no authentication and no user interaction (CVSS AV:N/AC:L/PR:N/UI:N). Any host that can reach the EPM service can attempt the traversal.
Exploitation
CISA added it to KEV on 2025-03-10 with a remediation due date of 2025-03-31, indicating known exploitation in the wild. EPSS is 0.99992 (99.987th percentile), and a third-party advisory carries an Exploit tag. No ransomware campaign use is documented.
What to do
- Apply the Ivanti EPM 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update immediately.
- If patching cannot be completed by the KEV due date, follow vendor mitigations or discontinue use of the product per BOD 22-01 guidance.
- Restrict network access to the EPM management interface to trusted administrative networks and block it from the internet.
- Rotate credentials and secrets that may reside on or be managed by the EPM server, since file contents may have been read.
- Review EPM logs and file access records for traversal attempts against the affected service.
Detection
- Search web/proxy and EPM logs for path traversal patterns such as absolute paths or ../ sequences in requests to the EPM service.
- Alert on unexpected outbound connections or file reads from the EPM server outside normal administrative activity.
- Monitor for access to sensitive files on the EPM host by the EPM service account and correlate with external source IPs.
- Hunt for post-exploitation use of credentials or configuration data obtained from EPM in authentication logs across managed endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-13159 to the Known Exploited Vulnerabilities catalog on 10 March 2025 as "Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 31 March 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-13159 | US Government Resource |
| https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilitie | ExploitThird Party Advisory |
Track CVE-2024-13159 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-13159), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.