Vulnerability record · CVE-2024-13161 · published 14 January 2025
CVE-2024-13161: Ivanti Endpoint Manager absolute path traversal leaks sensitive files
Ivanti · Endpoint Manager
Ivanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory. It affects EPM 2024 before the January-2025 Security Update and EPM 2022 SU6 before the January-2025 Security Update. Because the endpoint management server holds credentials and configuration for managed devices, leaked files can expose high-value data.
Description
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with known exploitation, has a very high EPSS score, and allows unauthenticated remote reading of sensitive data from a management server.
What it is
Ivanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory. It affects EPM 2024 before the January-2025 Security Update and EPM 2022 SU6 before the January-2025 Security Update. Because the endpoint management server holds credentials and configuration for managed devices, leaked files can expose high-value data.
Impact
An unauthenticated attacker gains read access to sensitive files on the EPM server, which can include credentials and configuration usable for further intrusion. There is no integrity or availability impact; the loss is confidentiality.
Attack surface
Reachable over the network via crafted path traversal requests to the EPM server; the CVSS vector shows no privileges and no user interaction required. No authentication is needed per the description and vector.
Exploitation
Listed in CISA KEV with a due date of 2025-03-31, indicating known exploitation in the wild, and EPSS is very high at roughly 0.90 (99.8th percentile). A third-party advisory is tagged as an exploit reference.
What to do
- Apply the Ivanti January-2025 Security Update for EPM 2024 or EPM 2022 SU6 as instructed in the vendor advisory.
- If patching cannot be completed by the KEV due date, follow vendor mitigations or discontinue use of the product per BOD 22-01 guidance.
- Restrict network access to the EPM server so only trusted management hosts can reach it.
- Rotate credentials and secrets that may reside on or be managed by the EPM server.
- Monitor vendor and CISA guidance for updated mitigations.
Detection
- Review EPM server and web logs for path traversal patterns such as ../ or encoded variants in request paths.
- Alert on file read requests to paths outside expected EPM directories.
- Hunt for anomalous access to configuration or credential files on the EPM host.
- Correlate EPM server activity with outbound connections or authentication attempts from unexpected sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-13161 to the Known Exploited Vulnerabilities catalog on 10 March 2025 as "Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 31 March 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-13161 | US Government Resource |
| https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilitie | ExploitThird Party Advisory |
Track CVE-2024-13161 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-13161), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.