This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: Ivanti EPM has a critical **Absolute Path Traversal** flaw. <br>๐ฅ **Consequences**: Remote attackers can **leak sensitive info** and coerce machine credentials for relay attacks.โฆ
โก **Threshold**: **LOW**. <br>๐ **Auth**: **None required** (Unauthenticated). <br>๐ **Access**: Remote (Network). <br>๐ค **UI**: No user interaction needed.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ฅ **Public Exp?**: **YES**. <br>๐ **PoC**: Available on GitHub (e.g., `horizon3ai/Ivanti-EPM-Coercion-Vulnerabilities`). <br>๐ ๏ธ **Tools**: Nuclei templates exist for automated scanning.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: <br>1. Scan for **Ivanti EPM** endpoints. <br>2. Use **Nuclei** with CVE-2024-13159 template. <br>3. Look for **UNC path** injection points in `GetHashForWildcardRecursive`.
Q8Is it fixed officially? (Patch/Mitigation)
๐ฉน **Official Fix**: **YES**. <br>๐ข **Advisory**: Ivanti released a security advisory in **Jan 2025**. <br>โ **Action**: Update to the latest patched version immediately.