CVE-2024-10811
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 36
Summary
CVE-2024-10811 is a newly disclosed vulnerability affecting Ivanti Endpoint Manager (EPM) versions prior to the January-2025 Security Update and 2022 SU6 January-2025 Security Update. This issue permits unauthenticated attackers to conduct absolute path traversal, thereby gaining unauthorized access to sensitive information on the targeted system. The vulnerability poses a significant risk, as it can be exploited remotely without requiring any valid credentials. The latest security updates from Ivanti are recommended to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.