First published: Tue Sep 29 2020(Updated: )
An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently obtain information about the cartography of the internal networks to which the product has access.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine | <10.0.511 | |
Zohocorp Manageengine Application Control Plus | <10.0.511 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-15595.
The affected software is Zoho Application Control Plus version up to 10.0.511.
The severity of CVE-2020-15595 is medium with a CVSSv3 score of 4.3.
An attacker can exploit this vulnerability by using the Element Configuration feature to retrieve the list of IP ranges and subnets configured in the product.
There is no information available regarding a fix for this vulnerability. It is recommended to follow the recommendations provided by the vendor or security advisory.