← Vulnerability feed

Vulnerability record · CVE-2024-13160 · published 14 January 2025

CVE-2024-13160: Ivanti Endpoint Manager absolute path traversal information leak

Ivanti · Endpoint Manager

Ivanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that allows a remote, unauthenticated attacker to read files outside the intended directory. It affects EPM before the 2024 January-2025 Security Update and the 2022 SU6 January-2025 Security Update. Because it exposes sensitive information without credentials, it is a serious exposure risk for EPM deployments.

7.5 CVSS 3.1 High CISA KEV since 10 Mar 2025 EPSS 91% · top 0.2% CWE-36 · CWE-36
7.5CVSS 3.1 base score
91%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is remotely exploitable without authentication, listed in CISA KEV as actively exploited, and carries a very high EPSS probability.

What it is

Ivanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that allows a remote, unauthenticated attacker to read files outside the intended directory. It affects EPM before the 2024 January-2025 Security Update and the 2022 SU6 January-2025 Security Update. Because it exposes sensitive information without credentials, it is a serious exposure risk for EPM deployments.

Impact

An attacker gains read access to sensitive files on the EPM server, which can include configuration data or credentials useful for follow-on attacks. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality.

Attack surface

Reachable over the network with no authentication and no user interaction required (CVSS AV:N/PR:N/UI:N). Any host that can reach the exposed EPM service can attempt the traversal.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-03-10, indicating active exploitation, and EPSS shows a 30-day probability of 0.91247 (99.8th percentile). A third-party advisory is tagged as an exploit reference.

What to do

  • Apply the Ivanti EPM 2024 January-2025 Security Update or the 2022 SU6 January-2025 Security Update as directed by the vendor advisory.
  • If patching cannot be completed by the CISA due date (2025-03-31), apply vendor-provided mitigations or discontinue use of the product per BOD 22-01 guidance.
  • Restrict network access to the EPM management interface to trusted administrative networks and block it from untrusted or internet-facing exposure.
  • Rotate credentials and secrets that may have been stored on or accessible from the EPM server.
  • Monitor vendor and CISA guidance for updated mitigation instructions.

Detection

  • Review EPM server and web logs for path traversal patterns such as ../ or encoded variants in request paths.
  • Alert on unexpected outbound or file-read activity from the EPM service account targeting configuration or credential files.
  • Hunt for access to EPM endpoints from hosts outside the expected administrative network range.
  • Correlate EPM server file access events with external connection sources around the time of suspected exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-13160 to the Known Exploited Vulnerabilities catalog on 10 March 2025 as "Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 31 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-13160 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-29824Ivanti Endpoint Manager Core Server SQL Injection Enables RCEIvanti Endpoint Manager 2022 SU5 and earlier contains an unspecified SQL injection in the Core server. An unauthenticated attacker on the same networ…KEVEPSS 100%analysed7.5CVE-2026-1603Ivanti Endpoint Manager authentication bypass leaks stored credentialsIvanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a func…KEVEPSS 88%analysed7.5CVE-2024-13159Ivanti EPM absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 100%analysed7.5CVE-2024-13161Ivanti Endpoint Manager absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 90%analysed9.9CVE-2020-13774Ivanti endpoint manager unrestricted file upload vulnerabilityAn unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…EPSS 5.0%9.8CVE-2024-50330Ivanti endpoint manager sql injection vulnerabilitySQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated at…EPSS 40%9.8CVE-2024-29847Ivanti EPM agent portal deserialization allows unauthenticated RCEThe agent portal in Ivanti Endpoint Manager (EPM) deserializes untrusted data, allowing a remote unauthenticated attacker to execute code. The flaw a…EPSS 53%analysed9.8CVE-2024-8191Ivanti endpoint manager sql injection vulnerabilitySQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achie…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2024-13160), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.