Vulnerability identifier: #VU60180
Vulnerability risk: Low
CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-284
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Zoho ManageEngine OpManager
Client/Desktop applications /
Other client software
Vendor: Zoho Corporation
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in NCM. A remote user can bypass implemented security restrictions and view alarms of other devices in alarm popups and dashboard widget.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Zoho ManageEngine OpManager: 12.5 125559 - 12.5 125564
External links
http://www.manageengine.com/network-monitoring/help/read-me-complete.html#125565
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.