SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-11686

Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible…

MEDIUM 6.1EPSS 2.29%

Does this matter?

Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.

Description

Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.29% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zohocorp/manageengine eventlog analyzer
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.