CVE-2024-13161Active Exploitation(ivanti / endpoint_manager)

LOWCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for ivanti endpoint_manager systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-31. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-36

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
endpoint_manager

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-02: 2Active Exploitation · 2026-05-02: 2Technical Details · 2026-05-02: 105-02
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-13161: CISA added Ivanti EPM CVE-2024-13161 to KEV: an absolute path traversal letting remote, unauth attackers leak sensitive data. What happened CISA added CVE-2024-13161 to the Known Exploited Vulnerabilities (KEV) catalog, signaling confirmed exploitation in…

    Post summary

    CISA has added CVE-2024-13161 to its KEV catalog, indicating that this absolute path traversal vulnerability in Ivanti EPM is being actively exploited to allow remote unauthenticated attackers to read sensitive data.

    1001063
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-13161-endpoint-manager-epm #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text announces that CVE‑2024‑13161 is actively being exploited in the wild, as indicated by the URL slug "active-exploit" and the CVE reference.

    0001035
    152 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager---
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2024--

Explore more