6.5

CVE-2023-31492

Exploit

Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Admanager Plus Version7.1 Update-
ZohocorpManageengine Admanager Plus Version7.1 Update7100
ZohocorpManageengine Admanager Plus Version7.1 Update7101
ZohocorpManageengine Admanager Plus Version7.1 Update7102
ZohocorpManageengine Admanager Plus Version7.1 Update7110
ZohocorpManageengine Admanager Plus Version7.1 Update7111
ZohocorpManageengine Admanager Plus Version7.1 Update7112
ZohocorpManageengine Admanager Plus Version7.1 Update7113
ZohocorpManageengine Admanager Plus Version7.1 Update7114
ZohocorpManageengine Admanager Plus Version7.1 Update7115
ZohocorpManageengine Admanager Plus Version7.1 Update7116
ZohocorpManageengine Admanager Plus Version7.1 Update7117
ZohocorpManageengine Admanager Plus Version7.1 Update7118
ZohocorpManageengine Admanager Plus Version7.1 Update7120
ZohocorpManageengine Admanager Plus Version7.1 Update7121
ZohocorpManageengine Admanager Plus Version7.1 Update7122
ZohocorpManageengine Admanager Plus Version7.1 Update7123
ZohocorpManageengine Admanager Plus Version7.1 Update7124
ZohocorpManageengine Admanager Plus Version7.1 Update7125
ZohocorpManageengine Admanager Plus Version7.1 Update7126
ZohocorpManageengine Admanager Plus Version7.1 Update7130
ZohocorpManageengine Admanager Plus Version7.1 Update7131
ZohocorpManageengine Admanager Plus Version7.1 Update7140
ZohocorpManageengine Admanager Plus Version7.1 Update7141
ZohocorpManageengine Admanager Plus Version7.1 Update7150
ZohocorpManageengine Admanager Plus Version7.1 Update7151
ZohocorpManageengine Admanager Plus Version7.1 Update7160
ZohocorpManageengine Admanager Plus Version7.1 Update7161
ZohocorpManageengine Admanager Plus Version7.1 Update7162
ZohocorpManageengine Admanager Plus Version7.1 Update7163
ZohocorpManageengine Admanager Plus Version7.1 Update7170
ZohocorpManageengine Admanager Plus Version7.1 Update7171
ZohocorpManageengine Admanager Plus Version7.1 Update7180
ZohocorpManageengine Admanager Plus Version7.1 Update7181
ZohocorpManageengine Admanager Plus Version7.1 Update7182
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.24% 0.469
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.