First published: Fri Aug 23 2024(Updated: )
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ServiceDesk Plus | <=14.7 | |
Zoho ManageEngine ServiceDesk Plus | =14.8-14810 | |
Zoho ManageEngine ServiceDesk Plus MSP | <=14.7 | |
Zoho ManageEngine ServiceDesk Plus MSP | =14.8-14800 | |
ManageEngine SupportCenter Plus | <=14.7 | |
ManageEngine SupportCenter Plus | =14.8-14800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38869 is classified as a critical vulnerability due to its potential to allow unauthorized access in remote office deploy configurations.
To address CVE-2024-38869, users should upgrade to Endpoint Central versions 11.3.2416.04 or 11.3.2400.25 or later.
CVE-2024-38869 affects ManageEngine Endpoint Central, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus versions prior to their specified fixed versions.
Yes, due to incorrect authorization, CVE-2024-38869 may allow unauthorized users to access sensitive data, potentially leading to data breaches.
CVE-2024-38869 specifically involves vulnerabilities in remote office deploy configurations that lack proper authorization.