CVE-2024-13160

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 36

Summary

CVE-2024-13160 is a newly discovered vulnerability in Ivanti Endpoint Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update. This absolute path traversal issue enables unauthenticated attackers to access sensitive information remotely. By manipulating file paths, an attacker can bypass access controls and potentially gain unauthorized access to confidential data. This vulnerability poses a significant risk to organizations using affected versions of Ivanti EPM and necessitates immediate attention and patch application to mitigate the exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share