8.8

CVE-2023-29505

An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Network Configuration Manager Version 12.6 Update build126165
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.07% 0.616
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
MITRE 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://excellium-services.com/cert-xlm-advisory/CVE-2023-29505
Third Party Advisory
https://www.manageengine.com/itom/advisory/cve-2023-29505.html
https://www.manageengine.com/network-monitoring/help/read-me-complete.html#build_127131
Release Notes
https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-29505