#VU31933 Improper Authentication in Zoho ManageEngine Desktop Central - CVE-2020-15589
Published: July 27, 2020 / Updated: October 10, 2020
Zoho ManageEngine Desktop Central
Zoho Corporation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in agent-server communication in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate functions within the client application. An attacker controlled server can force the client application to skip TLS certificate validation and perform a MitM attack or compromise the affected system.