The Cybersecurity and Infrastructure Security Agency (CISA) updated its KEV catalog on March 10, 2025, to include three newly identified vulnerabilities in Ivanti Endpoint Manager (EPM), a widely used enterprise software for managing endpoints.
The KEV catalog tracks vulnerabilities actively exploited in the wild, urging organizations to prioritize remediation to safeguard critical systems.
All three vulnerabilities CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161 are classified as absolute path traversal issues (CWE-36), with identical characteristics:
Each flaw enables a remote, unauthenticated attacker to access sensitive files by manipulating file paths, potentially exposing configuration data, credentials, or other critical information.
These vulnerabilities stem from inadequate path validation in Ivanti EPM’s file-handling processes. An attacker can send crafted HTTP requests—such as GET /../../sensitive/file—to traverse the file system beyond intended directories.
If successful, this could reveal files like logs or configuration settings without requiring authentication, providing a foothold for further attacks.
While it’s unknown if these vulnerabilities are tied to ransomware campaigns, their presence in the KEV catalog indicates confirmed exploitation in real-world scenarios. Given Ivanti EPM’s role in managing enterprise endpoints, leaks of sensitive data could lead to broader network compromises, making timely action critical.
The addition of CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161 to CISA’s KEV catalog underscores the growing threat to endpoint management systems.
With a three-week remediation window for federal agencies, enterprises using Ivanti EPM should act swiftly to mitigate risks and prevent potential data leaks from escalating into larger breaches.
Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…