CVE-2020-8422: Medium severity ZohoCorp Manageengine Remote Access Plus vulnerability
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description (but not the password).
Affected Software
Event History
Frequently Asked Questions
What vulnerability was discovered in Zoho ManageEngine Remote Access Plus?
An authorization issue was discovered in the Credential Manager feature.
What is the severity of CVE-2020-8422?
The severity of CVE-2020-8422 is medium with a CVSS score of 4.3.
How does CVE-2020-8422 vulnerability affect Zoho ManageEngine Remote Access Plus?
The vulnerability allows a user with the Guest role to extract the collection of all defined credentials of remote machines.
What is the affected version of Zoho ManageEngine Remote Access Plus?
The affected version of Zoho ManageEngine Remote Access Plus is up to exclusive version 10.0.450.
Is there any further information available about CVE-2020-8422?
Yes, you can find more information about CVE-2020-8422 in the following references: [link1](https://excellium-services.com/cert-xlm-advisory/CVE-2020-8422), [link2](https://excellium-services.com/cert-xlm-advisory/cve-2020-8422/).