4.3

CVE-2022-24446

An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6100
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6150
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6151
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6160
ZohocorpManageengine Key Manager Plus Version6.1.6 Updatebuild6161
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.01% 0.829
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N