Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
Attack Vector (AV) | Network | Adjacent | Local | Physical |
---|---|---|---|---|
Attack Complexity (AC) | LOW | High | ||
Privileges Required (PR) | None | Low | High | |
User Interaction (UI) | None | Required | ||
Scope (S) | Unchange | Change | ||
Confidentiality (C) | None | Low | High | |
Integrity (I) | None | Low | High | |
Availability (A) | None | Low | High |
Attack Vector (AV) | Network | Adjacent | Local |
---|---|---|---|
Access Complexity (AC) | Low | Medium | High |
Authentication (Au) | None | Single | Multiple |
Confidentiality (C) | None | Parical | Complete |
Integrity (I) | None | Partial | Complete |
Availability (A) | None | Partial | Complete |
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag: Wordpress(17 tweets)
List of frequently cited URLs
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
alerts.vulmon.com | 259 |
cvetrends.com | 51 |
pitstop.manageengine.com | 10 |
securityaffairs.co | 6 |
thehackernews.com | 5 |
threatpost.com | 4 |
securityonline.info | 3 |
Name | URL |
---|---|
No Data |
Name | URL |
---|---|
No Data |