CVE-2018-11716: Critical severity manageengine desktop central vulnerability
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11716?
The severity of CVE-2018-11716 is critical (9.8).
How can an unauthenticated attacker access log files in Zoho ManageEngine Desktop Central?
An unauthenticated remote attacker can access log files in Zoho ManageEngine Desktop Central.
What kind of information can be found in the log files of Zoho ManageEngine Desktop Central?
The log files of Zoho ManageEngine Desktop Central may contain critical information such as private information, location of enrolled devices, cleartext passwords, patching level, etc.
What is the affected software version of CVE-2018-11716?
The affected software version of CVE-2018-11716 is Zoho ManageEngine Desktop Central before 100230.
Is authentication required to exploit CVE-2018-11716?
No, authentication is not required to exploit CVE-2018-11716.