{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-13160",
  "revision": 1,
  "title": "Ivanti Endpoint Manager — path traversal (CVE-2024-13160)",
  "summary": "Ivanti Endpoint Manager (EPM) before the January 2025 security updates lets an unauthenticated request name an absolute path and read the file back. It is one of several identically described traversals fixed together.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.5,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "version": "3.1"
  },
  "epss": 0.91247,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2025-03-10",
    "prerequisites": "Network access to the Endpoint Manager server; no credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1083"
  ],
  "kill_chain": "collection",
  "recommended_action": "Apply the January 2025 security update for Endpoint Manager 2024 or 2022 SU6 now; one update closes this and its siblings at once.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-13160",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-13160",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-13160",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13160",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6"
    },
    {
      "type": "exploit",
      "url": "https://www.horizon3.ai/attack-research/attack-blogs/ivanti-endpoint-manager-multiple-credential-coercion-vulnerabilities/"
    }
  ],
  "published_at": "2025-01-14T18:15:26.447Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "ivanti",
    "endpoint-manager",
    "path-traversal",
    "information-disclosure",
    "kev"
  ]
}
