CVE-2024-10811

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 36

Summary

CVE-2024-10811 is a newly disclosed vulnerability affecting Ivanti Endpoint Manager (EPM) versions prior to the January-2025 Security Update and 2022 SU6 January-2025 Security Update. This issue permits unauthenticated attackers to conduct absolute path traversal, thereby gaining unauthorized access to sensitive information on the targeted system. The vulnerability poses a significant risk, as it can be exploited remotely without requiring any valid credentials. The latest security updates from Ivanti are recommended to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share