LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-13160: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 10, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 31, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-13160 to its Known Exploited Vulnerabilities catalog on Mar 10, 2025, with a federal patch deadline of Mar 31, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-13160 is an absolute path traversal vulnerability in Ivanti Endpoint Manager (EPM). It allows a remote unauthenticated attacker to leak sensitive information from the system. Endpoint management platforms like EPM sit at the center of device inventory, software deployment, and configuration control, so information disclosure here can give attackers useful details for further targeting of the environment. Confirm all product details and fixes against the vendor advisory.

How it works

The underlying weakness is CWE-36, absolute path traversal. In this class of flaw, an application fails to properly constrain file-system paths supplied by a user. An attacker can craft a request that references an absolute path outside the intended directory, causing the application to read and return file contents it should never expose.

According to the CISA summary, a remote unauthenticated attacker can exploit this in Ivanti EPM to leak sensitive information. No further exploit mechanics, request formats, or specific file targets are provided in the available facts; treat any public proof-of-concept claims with caution and validate them only against official vendor guidance. The practical result is unauthorized disclosure of data that the EPM process can access, which may include configuration files, credentials, or other operational details.

Am I affected? How to find it in your systems

Ivanti Endpoint Manager is typically deployed as a central management server (or set of servers) used by IT and security teams to inventory, patch, and configure endpoints. It often runs on Windows servers inside the corporate network or in hybrid/cloud-managed setups and is reachable by management consoles, agents, and sometimes remote administration interfaces.

Public detail on exact vulnerable configurations is limited; always confirm against the official Ivanti advisory.

How to remediate

The primary remediation is to apply the vendor-supplied update for Ivanti Endpoint Manager as directed in the official advisory. Follow the CISA required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted components, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls appropriate to absolute path traversal and unauthenticated information disclosure:

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to breaches in which sensitive configuration or operational data is stolen. If you suspect your EPM instance was targeted, treat any information the service could access as potentially compromised, rotate credentials, and investigate for follow-on activity. You can run a free exposure scan of your email addresses to check whether they appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager (EPM)
WeaknessCWE-36
Added to CISA KEVMar 10, 2025
Federal patch deadlineMar 31, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities