CVE-2024-38868: Incorrect Authorization
Published Aug 30, 2024
·Updated
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
Affected Software
2 affected components
ZohoCorp ManageEngine Endpoint Central<11.3.2400.15
ZohoCorp ManageEngine Endpoint Central>=11.3.2401.05<11.3.2406.08
Event History
Aug 30, 2024
CVE Published
via MITRE·05:44 PM
Data Sourced
via MITRE·05:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38868?
CVE-2024-38868 is categorized as a high severity vulnerability due to its impact on device isolation authorization.
2
How do I fix CVE-2024-38868?
To remediate CVE-2024-38868, upgrade ManageEngine Endpoint Central to version 11.3.2406.08 or later and ensure all updates are applied.
3
What versions of ManageEngine Endpoint Central are affected by CVE-2024-38868?
CVE-2024-38868 affects ManageEngine Endpoint Central versions prior to 11.3.2406.08 and 11.3.2400.15.
4
What type of vulnerability is CVE-2024-38868?
CVE-2024-38868 is classified as an incorrect authorization vulnerability.
5
Can CVE-2024-38868 lead to unauthorized device access?
Yes, CVE-2024-38868 can result in unauthorized access to devices due to improper authorization during isolation.