First published: Mon Jul 16 2018(Updated: )
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | <100230 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11716 is critical (9.8).
An unauthenticated remote attacker can access log files in Zoho ManageEngine Desktop Central.
The log files of Zoho ManageEngine Desktop Central may contain critical information such as private information, location of enrolled devices, cleartext passwords, patching level, etc.
The affected software version of CVE-2018-11716 is Zoho ManageEngine Desktop Central before 100230.
No, authentication is not required to exploit CVE-2018-11716.