CVE-2024-13161

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 36

Summary

CVE-2024-13161 is a newly disclosed vulnerability affecting Ivanti Environmental Policy Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update. This absolute path traversal issue enables unauthenticated remote attackers to access sensitive information by manipulating file paths. By exploiting this vulnerability, an attacker can potentially gain unauthorized access to data, posing a significant risk to an organization's security. It is essential for Ivanti EPM users to apply the security updates immediately to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share