CVE-2024-13160 Details
Description
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 November security update and prior, as well as 2022 SU6 November security update and prior. This vulnerability allows remote unauthenticated attackers to leak sensitive information by exploiting the application's web API endpoints related to vulnerability management.
Users are advised to update to the Ivanti EPM 2024 January-2025 Security Update or the Ivanti EPM 2022 SU6 January-2025 Security Update. Hot patch instructions for both versions are available on the Ivanti Community.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-13160 | CISA-ADP | US Government Resource |
| https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilities/ | CISA-ADP | ExploitThird Party Advisory |
| https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6 | ivanti | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Mar 10, 2025 | Mar 31, 2025 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-36 | Absolute Path Traversal | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | < 2022 2022 - 2022 su1 2022 su2 2022 su3 2022 su4 2022 su5 2022 su6 2024 - |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | ivanti |
| Oct 24, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 13, 2025 | Initial Analysis | [email protected] |
| Mar 11, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Feb 21, 2025 | CVE Modified | CISA-ADP |
| Jan 14, 2025 | New CVE Received | ivanti |