Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
CVE-2024-13160 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | exploitation_technique | T1190 | Exploit Public-Facing Application |
Comments
An attacker can exploit this vulnerability to coerce credential relay attacks and gain access to sensitive information.
References
|
CVE-2024-13160 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | exploitation_technique | T1558 | Steal or Forge Kerberos Tickets |
Comments
An attacker can exploit this vulnerability to coerce credential relay attacks and gain access to sensitive information.
References
|
CVE-2024-13160 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | primary_impact | T1550.002 | Pass the Hash |
Comments
An attacker can exploit this vulnerability to coerce credential relay attacks and gain access to sensitive information.
References
|
CVE-2024-13160 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | secondary_impact | T1087 | Account Discovery |
Comments
An attacker can exploit this vulnerability to coerce credential relay attacks and gain access to sensitive information.
References
|