First published: Fri Aug 04 2023(Updated: )
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Network Configuration Manager | =12.6-build126165 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29505 is an issue discovered in Zoho ManageEngine Network Configuration Manager 12.6.165 that allows Cross-site WebSocket hijacking.
CVE-2023-29505 has a severity level of high (8.8).
CVE-2023-29505 affects Zoho ManageEngine Network Configuration Manager 12.6.165.
To fix CVE-2023-29505, update to the latest version of Zoho ManageEngine Network Configuration Manager (build 127131).
You can find more information about CVE-2023-29505 at the following references: [Reference 1](https://excellium-services.com/cert-xlm-advisory/CVE-2023-29505), [Reference 2](https://www.manageengine.com/network-monitoring/help/read-me-complete.html#build_127131), [Reference 3](https://www.manageengine.com/itom/advisory/cve-2023-29505.html).