CVE-2024-13158 Details
Description
An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
A vulnerability exists in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows remote authenticated attackers with admin privileges to execute code by exploiting an unbounded resource search path.
Users can apply the Security Hot Patch available for their EPM version. For EPM 2024, the patch can be downloaded from the Ivanti License System (ILS) and applied to the core server and remote consoles. For EPM 2022 SU6, a similar process applies. After applying the patch, the Core Server should be rebooted.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6 | ivanti | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ivanti |
| CWE-426 | Untrusted Search Path | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | < 2024 2022 - 2022 su1 2022 su2 2022 su3 2022 su4 2022 su5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 12, 2025 | Initial Analysis | [email protected] |
| Jan 14, 2025 | New CVE Received | ivanti |