Vulnerability Details CVE-2024-13160
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.907
EPSS Ranking 99.6%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Ransomware Campaign
Unknown
Products affected by CVE-2024-13160
-
cpe:2.3:a:ivanti:endpoint_manager:2021.1.1
-
cpe:2.3:a:ivanti:endpoint_manager:2022
-
cpe:2.3:a:ivanti:endpoint_manager:2024