S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 25, 2025

CVE-2024-13161 Scanner

Ivanti EPM - Credential Coercion Vulnerability in GetHashForSingleFile CVE-2024-13161 Scanner

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-13161
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Endpoint Managerby Ivanti
2024 January-2025 Security Update
Updated Aug 22, 2026View on NVD →
Detail

Ivanti Endpoint Manager (EPM) is a comprehensive endpoint management solution widely used by organizations to manage and secure their IT infrastructure. It provides capabilities such as software distribution, patch management, and security configuration. This product is essential for managing corporate endpoints, ensuring that they remain secure, compliant, and well-maintained across an organization's network. However, like many networked systems, Ivanti EPM is susceptible to vulnerabilities that can compromise its effectiveness and expose critical assets to attackers. The vulnerability in question is found within a specific endpoint of Ivanti EPM and can be exploited remotely by unauthenticated attackers. The affected version and more specific version details are not provided, but the vulnerability itself can severely impact the security of the system.

The vulnerability identified in Ivanti Endpoint Manager involves improper input validation within the GetHashForSingleFile endpoint. This flaw allows an unauthenticated attacker to coerce the EPM machine account credentials via the use of a remote UNC path. When an attacker specifies a crafted wildcard parameter, the EPM system triggers NTLM authentication, which could potentially expose sensitive credentials. This type of vulnerability is categorized as a credential coercion issue and has a critical CVSS score of 9.8. Exploitation of this vulnerability could lead to unauthorized access or disclosure of credentials, which could facilitate further attacks on the system.

The vulnerability resides in the GetHashForSingleFile function of Ivanti EPM, where the wildcard parameter is improperly validated. This improper validation allows an attacker to inject a malicious UNC path in the wildcard parameter, triggering NTLM authentication. The attacker can then coerce the system to authenticate to an attacker-controlled server, leaking sensitive credentials such as machine account credentials. The attack does not require any authentication, making it a severe remote unauthenticated attack vector. The vulnerable parameter is the wildcard used in the SOAP request body, and the exploitation of this vulnerability is contingent on the system’s failure to properly validate this input.

If successfully exploited, this vulnerability allows an attacker to coerce sensitive machine account credentials through NTLM authentication. These credentials may be used in further attacks, such as lateral movement within the network, privilege escalation, or data exfiltration. The attacker can potentially access restricted systems or compromise the overall security of the network. Exploiting this vulnerability could also result in a full compromise of the targeted endpoint, making it a high-impact attack. Organizations relying on Ivanti Endpoint Manager for endpoint security and management could face significant risks if this vulnerability is not mitigated.

REFERENCES

Solution Advice
  • Ensure proper input validation on all parameters in vulnerable SOAP endpoints.
  • Use NTLM authentication in a secure manner, ensuring that sensitive credentials are not exposed to unauthorized users.
  • Regularly update Ivanti Endpoint Manager to patch known vulnerabilities.
  • Limit access to the affected endpoint to trusted sources and networks only.
  • Monitor authentication logs for suspicious NTLM authentication attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.