Updates address 4 critical and 12 high severity vulnerabilities
Summary
Updates address 4 critical and 12 high severity vulnerabilities
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Ivanti has released a security advisory addressing 16 vulnerabilities affecting Endpoint Manager (EPM) products. Ivanti EPM is an all-in-one solution for managing device endpoints within a network.
Four vulnerabilities designated as CVE-2024-10811, CVE-2024-13161, CVE-2024-13160, and CVE-2024-13159 with a CVSSv3 score of 9.8 could allow an unauthenticated, remote attacker to leak sensitive information via path traversal.
CVE-2024-13161, CVE-2024-13160, and CVE-2024-13159 are reported as exploited in the wild and have been added to CISA's Known Exploited Vulnerability Catalog.
The other high severity vulnerabilities leading to remote code execution (RCE), privilege escalation, or denial-of-service (DoS) were also addressed.
Threat updates
Remediation advice
Affected organisations are encouraged to review Security Advisory EPM January 2025 for EPM 2024 and EPM 2022 SU6 and apply the relevant security updates as soon as practicable.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 11 March 2025 2:41 pm