Security features bypass in Zoho ManageEngine EventLog Analyzer - CVE-2023-35785

 

Security features bypass in Zoho ManageEngine EventLog Analyzer - CVE-2023-35785

Published: June 21, 2023


Vulnerability identifier: #VU77579
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35785
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an unspecified error. A remote attacker can bypass implemented security restrictions.


Affected software

Zoho ManageEngine EventLog Analyzer
Log360
Zoho ManageEngine ServiceDesk Plus MSP
Zoho ManageEngine ADAudit Plus
Zoho ManageEngine ADManager Plus
Zoho ManageEngine SupportCenter Plus
ManageEngine AssetExplorer

How to mitigate CVE-2023-35785

Install updates from vendor's website.

Zoho ManageEngine EventLog Analyzer - update to 12302
Log360 - update to 5316
Zoho ManageEngine ADAudit Plus - update to 7203
Zoho ManageEngine ADManager Plus - update to 7201
Zoho ManageEngine SupportCenter Plus - update to 14301
Zoho ManageEngine ServiceDesk Plus MSP - update to 14301
ManageEngine AssetExplorer - update to 7003

External References

Related Security Bulletins