4.3

CVE-2022-24446

An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6100
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6150
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6151
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6160
Zohocorp ≫ Manageengine Key Manager Plus Version 6.1.6 Update build6161
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.94% 0.57
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://excellium-services.com/cert-xlm-advisory/cve-2022-24446/
Third Party Advisory
https://www.manageengine.com/key-manager/release-notes.html#6200
Vendor Advisory
Release Notes
https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24446