CVE-2018-11717
Last modified
CVE-2018-11717 is a vulnerability of currently unknown severity. An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD account used to send mail), the cleartext password of recovery_password of Android devices, the cleartext password of account "set", the location of devices enrolled in the platform (with UUID and information related to the name of the person at the location), critical information about all enrolled devices such as Serial Number, UUID, Model, Name, and auth_session_token (usable to spoof a terminal identity on the platform), etc.. EPSS estimates a 8.58% chance of exploitation in the next 30 days.
Description
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD account used to send mail), the cleartext password of recovery_password of Android devices, the cleartext password of account "set", the location of devices enrolled in the platform (with UUID and information related to the name of the person at the location), critical information about all enrolled devices such as Serial Number, UUID, Model, Name, and auth_session_token (usable to spoof a terminal identity on the platform), etc.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Desktop Central | < 100251 |
References
- https://blog.netxp.fr/manageengine-deep-exploitation/Exploit, Third Party Advisory
- https://blog.netxp.fr/manageengine-deep-exploitation/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11717?
How severe is CVE-2018-11717?
How do I fix CVE-2018-11717?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-11711A remote attacker can bypass the System Manager Mode on the …
- CVE-2018-11712WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp…
- CVE-2018-11713WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp…
- CVE-2018-11714An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9…
- CVE-2018-11715The Recent Threads plugin before 1.1 for MyBB allows XSS via…
- CVE-2018-11716An issue was discovered in Zoho ManageEngine Desktop Central…
- CVE-2018-11718Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF.
- CVE-2018-11719Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE.
- CVE-2018-1172This vulnerability allows remote attackers to deny service o…
- CVE-2018-11720Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directo…
- CVE-2018-11722WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'c…
- CVE-2018-11723The libpff_name_to_id_map_entry_read function in libpff_name…
Are you affected by CVE-2018-11717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
