LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-13161: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 10, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 31, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-13161 to its Known Exploited Vulnerabilities catalog on Mar 10, 2025, with a federal patch deadline of Mar 31, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-13161 is an absolute path traversal vulnerability in Ivanti Endpoint Manager (EPM). It allows a remote unauthenticated attacker to leak sensitive information from affected systems. Endpoint management platforms like EPM typically hold inventory data, configuration details, and credentials used across the enterprise, so information disclosure here can give attackers a foothold for further reconnaissance or lateral movement. Confirm all product-specific details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-36 (Absolute Path Traversal). In this class of flaw, an application fails to properly restrict file or path references supplied by a remote party. An attacker can supply crafted input that resolves to absolute filesystem locations outside the intended directory, causing the application to return or expose content that should remain inaccessible. According to the CISA summary, the result in Ivanti EPM is leakage of sensitive information without requiring authentication. Exact request formats, parameters, or file targets are not provided here; treat any public proof-of-concept claims with caution and validate them only against the official vendor advisory and your own lab testing.

Am I affected? How to find it in your systems

Ivanti Endpoint Manager is commonly deployed as a central management server that communicates with agents on endpoints for software distribution, inventory, and patching. It may run on-premises or in hybrid/cloud-managed configurations. Inventory steps:

Because the vulnerability is remote and unauthenticated, any internet-exposed or poorly segmented EPM instance should be treated as higher priority. Specific version ranges and fixed builds must be confirmed against the vendor advisory; do not rely on secondary sources alone.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation for Ivanti Endpoint Manager exactly as described in the official advisory. After patching:

Document the change window and retain evidence of the applied update for audit purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not eliminate the underlying vulnerability; schedule the permanent patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited information-disclosure flaws can lead to broader compromise once attackers obtain credentials, configuration files, or network maps. Known ransomware use of this specific CVE is not documented, yet the sensitive data potentially leaked by EPM remains valuable. If you suspect exposure, review EPM logs for signs of unauthorized access, rotate any credentials that may have been stored or cached by the product, and examine related systems for follow-on activity. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager (EPM)
WeaknessCWE-36
Added to CISA KEVMar 10, 2025
Federal patch deadlineMar 31, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities