6.5

CVE-2022-24447

An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Key Manager Plus Version6.0 Update6000
ZohocorpManageengine Key Manager Plus Version6.0 Update6001
ZohocorpManageengine Key Manager Plus Version6.0 Update6002
ZohocorpManageengine Key Manager Plus Version6.1 Update6100
ZohocorpManageengine Key Manager Plus Version6.1 Update6150
ZohocorpManageengine Key Manager Plus Version6.1 Update6151
ZohocorpManageengine Key Manager Plus Version6.1 Update6160
ZohocorpManageengine Key Manager Plus Version6.1 Update6161
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.5% 0.648
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N