LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-13159: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 10, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 31, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-13159 to its Known Exploited Vulnerabilities catalog on Mar 10, 2025, with a federal patch deadline of Mar 31, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-13159 is an absolute path traversal vulnerability in Ivanti Endpoint Manager (EPM). It allows a remote unauthenticated attacker to leak sensitive information from the system. Endpoint management platforms like EPM typically hold inventory data, credentials, configuration details, and other operational secrets, so unauthorized disclosure can give attackers a foothold for further reconnaissance or lateral movement. Organizations running EPM should treat this as a priority for inventory and remediation.

Public detail is limited to the CISA summary and the CWE classification; exact affected versions, attack vectors, and impact scoring must be confirmed against the vendor advisory.

How it works

The flaw is classified as CWE-36 (Absolute Path Traversal). In this class of weakness, an application fails to properly restrict file-system paths supplied by a remote party. An attacker can supply an absolute path that points outside the intended directory or resource, causing the application to read and return the contents of files it should not expose.

According to the CISA summary, a remote unauthenticated attacker can exploit this in Ivanti Endpoint Manager (EPM) to leak sensitive information. No further exploit mechanics, payloads, or prerequisites are provided in the available facts; defenders should assume any network-reachable EPM instance that has not been updated is potentially reachable by an unauthenticated party and should verify the precise conditions in the vendor advisory.

Am I affected? How to find it in your systems

Ivanti Endpoint Manager (EPM) is typically deployed as a central management console for endpoint inventory, software distribution, and patching. It commonly runs on Windows servers inside enterprise networks and may be reachable from management subnets, VPN ranges, or, in some configurations, the internet.

How to remediate

The primary remediation is to apply the vendor-supplied update for Ivanti Endpoint Manager (EPM) as directed in the official advisory. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to an unauthenticated information-leak vulnerability.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to breaches in which sensitive configuration data, credentials, or inventory details are stolen. Known ransomware use of this CVE is not documented in the available facts, but information leakage can still enable follow-on attacks. If you suspect exposure, review EPM and network logs for signs of unauthorized access, rotate any credentials that may have been stored or cached by the product, and assess whether downstream systems were reached. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager (EPM)
WeaknessCWE-36
Added to CISA KEVMar 10, 2025
Federal patch deadlineMar 31, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities