CVE-2023-29505: High severity manageengine network configuration manager vulnerability
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29505?
CVE-2023-29505 is an issue discovered in Zoho ManageEngine Network Configuration Manager 12.6.165 that allows Cross-site WebSocket hijacking.
What is the severity of CVE-2023-29505?
CVE-2023-29505 has a severity level of high (8.8).
How does CVE-2023-29505 affect Zoho ManageEngine Network Configuration Manager?
CVE-2023-29505 affects Zoho ManageEngine Network Configuration Manager 12.6.165.
How can I fix CVE-2023-29505?
To fix CVE-2023-29505, update to the latest version of Zoho ManageEngine Network Configuration Manager (build 127131).
Where can I find more information about CVE-2023-29505?
You can find more information about CVE-2023-29505 at the following references: [Reference 1](https://excellium-services.com/cert-xlm-advisory/CVE-2023-29505), [Reference 2](https://www.manageengine.com/network-monitoring/help/read-me-complete.html#build_127131), [Reference 3](https://www.manageengine.com/itom/advisory/cve-2023-29505.html).