CVE-2018-11716

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
16/07/2018
Last modified:
17/09/2018

Description

An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:*:*:*:* 100230 (excluding)