CVE-2024-10811 Details
Description
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows remote, unauthenticated attackers to exploit absolute path traversal, leading to the unauthorized disclosure of sensitive information. The issue arises from the application's failure to properly validate user input, enabling attackers to manipulate file paths and access restricted data.
Users should apply the January 2025 Security Update Hot Patch for their respective EPM version. This patch is available through the Ivanti License System (ILS). After applying the patch, it's recommended to run 'AgentEngineHashUpdate.exe' to refresh the agent hash values in the database.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilities/ | CISA-ADP | ExploitThird Party Advisory |
| https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6 | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-36 | Absolute Path Traversal | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | < 2022 2022 - 2022 su1 2022 su2 2022 su3 2022 su4 2022 su5 2024 - |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2025 | Initial Analysis | [email protected] |
| Feb 21, 2025 | CVE Modified | CISA-ADP |
| Jan 14, 2025 | New CVE Received | ivanti |