CVE-2024-13161
CRITICAL KEV NUCLEIIvanti EPM - Path Traversal
Title source: llmDescription
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
Nuclei Templates (1)
Ivanti EPM - Credential Coercion Vulnerability in GetHashForSingleFile
CRITICALVERIFIEDby ritikchaddha
Shodan:
http.favicon.hash:362091310
FOFA:
icon_hash="362091310"
References (3)
Scores
CVSS v3
9.8
EPSS
0.9260
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2025-03-10
VulnCheck KEV
2025-03-10
ENISA EUVD
EUVD-2024-51387
Classification
CWE
CWE-36
Status
published
Affected Products (9)
ivanti/endpoint_manager
< 2022
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
Timeline
Published
Jan 14, 2025
KEV Added
Mar 10, 2025
Tracked Since
Feb 18, 2026