4.3

CVE-2022-24446

An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6100
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6150
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6151
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6160
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6161
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.01% 0.829
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N