CVE-2023-29443: XEE

Published Apr 26, 2023
·
Updated

Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

Affected Software

22 affected components
Zohocorp Manageengine Assetexplorer=6.9-6980
Zohocorp Manageengine Assetexplorer=6.9-6981
Zohocorp Manageengine Assetexplorer=6.9-6982
Zohocorp Manageengine Assetexplorer=6.9-6983
Zohocorp Manageengine Assetexplorer=6.9-6984
Zohocorp Manageengine Assetexplorer=6.9-6985
Zohocorp Manageengine Assetexplorer=6.9-6986
Zohocorp Manageengine Assetexplorer=6.9-6987
Zohocorp Manageengine Assetexplorer=6.9-6988
Zohocorp ManageEngine ServiceDesk Plus<14.1
Zohocorp ManageEngine ServiceDesk Plus=14.1
Zohocorp ManageEngine ServiceDesk Plus=14.1-14100
Zohocorp ManageEngine ServiceDesk Plus=14.1-14101
Zohocorp ManageEngine ServiceDesk Plus=14.1-14102
Zohocorp ManageEngine ServiceDesk Plus=14.1-14103
Zohocorp ManageEngine ServiceDesk Plus=14.1-14104
ZohoCorp ManageEngine ServiceDesk Plus MSP<14.0
ZohoCorp ManageEngine ServiceDesk Plus MSP=14.0-14000
ZohoCorp ManageEngine ServiceDesk Plus MSP=14.0-14001
Zohocorp Manageengine Supportcenter Plus<14.0
Zohocorp Manageengine Supportcenter Plus=14.0-14000
Zohocorp Manageengine Supportcenter Plus=14.0-14001

Event History

Apr 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-29443?

CVE-2023-29443 is a vulnerability in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus, and AssetExplorer that allows SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

2

What software versions are affected by CVE-2023-29443?

Versions of Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 are affected by CVE-2023-29443.

3

How severe is CVE-2023-29443?

CVE-2023-29443 has a severity level of 4.9 out of 10, which is considered medium.

4

What is the Common Weakness Enumeration (CWE) for CVE-2023-29443?

The CWE for CVE-2023-29443 is CWE-611.

5

Is there a fix for CVE-2023-29443?

Yes, upgrading to versions 14105 for Zoho ManageEngine ServiceDesk Plus, 14200 for ServiceDesk Plus MSP and SupportCenter Plus, and 6989 for AssetExplorer will fix the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203