Cleartext transmission of sensitive information in Zoho ManageEngine ServiceDesk Plus MSP - #VU72420

 

Cleartext transmission of sensitive information in Zoho ManageEngine ServiceDesk Plus MSP - #VU72420

Published: February 20, 2023


Vulnerability identifier: #VU72420
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel in backup scheduling to transmit passwords. A remote attacker with ability to intercept network traffic can gain access to sensitive data.


Affected software

Zoho ManageEngine ServiceDesk Plus MSP
Zoho ManageEngine SupportCenter Plus

Remediation

Install updates from vendor's website.

Zoho ManageEngine ServiceDesk Plus MSP - update to 14001
Zoho ManageEngine SupportCenter Plus - update to 14001

External References

Related Security Bulletins