Cleartext transmission of sensitive information in Zoho ManageEngine ServiceDesk Plus MSP - #VU72420
Published: February 20, 2023
Vulnerability identifier: #VU72420
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel in backup scheduling to transmit passwords. A remote attacker with ability to intercept network traffic can gain access to sensitive data.
Affected software
Zoho ManageEngine ServiceDesk Plus MSP
Zoho ManageEngine SupportCenter Plus
Zoho ManageEngine SupportCenter Plus
Remediation
Install updates from vendor's website.
Zoho ManageEngine ServiceDesk Plus MSP - update to 14001
Zoho ManageEngine SupportCenter Plus - update to 14001
Zoho ManageEngine SupportCenter Plus - update to 14001