CVE-2018-11716
Last modified
CVE-2018-11716 is a vulnerability of currently unknown severity. An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.. EPSS estimates a 14.29% chance of exploitation in the next 30 days.
Description
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Desktop Central | < 100230 |
References
- https://blog.netxp.fr/manageengine-deep-exploitation/Exploit, Third Party Advisory
- https://blog.netxp.fr/manageengine-deep-exploitation/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11716?
How severe is CVE-2018-11716?
How do I fix CVE-2018-11716?
Are you affected by CVE-2018-11716?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
