Loading HuntDB...

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Added March 10, 2025 Due March 31, 2025 CVE-2024-13161
Overdue Ivanti / Endpoint Manager (EPM) CWE-36

Description

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.03.10
Catalog Released
March 10, 2025
Days Until Due
0 days
Last Updated
4 months, 2 weeks ago