4.3
CVE-2022-24446
- EPSS 0.94%
- Veröffentlicht 01.03.2022 02:15:07
- Zuletzt bearbeitet 30.05.2025 16:15:29
- Erkennungen
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6100
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6150
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6151
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6160
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6161
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.94% | 0.57 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
https://excellium-services.com/cert-xlm-advisory/cve-2022-24446/
https://www.manageengine.com/key-manager/release-notes.html#6200
https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24446