CVE-2020-8540: SSRF
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine Desktop Centralto a version that resolves this vulnerability.Fixed in 07-Mar-2020 - Compensating control
Mitigate exposure by restricting access to the affected Desktop Central endpoints (e.g., allow only trusted source IPs to reach the service that processes XML requests).
Event History
Frequently Asked Questions
What is CVE-2020-8540 vulnerability?
CVE-2020-8540 is an XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update.
What is the severity of CVE-2020-8540?
The severity of CVE-2020-8540 is critical with a CVSS score of 9.8.
How can remote attackers exploit CVE-2020-8540?
Remote unauthenticated users can exploit CVE-2020-8540 by reading arbitrary files or conducting server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Which versions of Zoho ManageEngine Desktop Central are affected by CVE-2020-8540?
Versions of Zoho ManageEngine Desktop Central up to and excluding the 07-Mar-2020 update are affected by CVE-2020-8540.
Is there a fix available for CVE-2020-8540?
Yes, the vulnerability can be fixed by updating Zoho ManageEngine Desktop Central to the version released on or after 07-Mar-2020.