Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2024 November security update
- <= 2022 SU6 November security update
This vulnerability is being actively exploited in the wild.
A path traversal vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 November security update and prior, as well as 2022 SU6 November security update and prior. This vulnerability allows remote unauthenticated attackers to leak sensitive information by exploiting the application's web API endpoints related to vulnerability management.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, with potential for further exploitation through credential coercion attacks, according to Horizon3.ai.
The vulnerability can be reproduced by sending a crafted request to the 'GetHashForWildcard' API endpoint. The 'wildcard' parameter can be manipulated to include a remote UNC path, which the Ivanti EPM server will then access, leading to information disclosure.
Users are advised to update to the Ivanti EPM 2024 January-2025 Security Update or the Ivanti EPM 2022 SU6 January-2025 Security Update. Hot patch instructions for both versions are available on the Ivanti Community.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.