CVE-2017-16924
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys. This is fixed in build 100157.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.60% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- zohocorp/manageengine desktop central
- Source
- cve@mitre.org
References
- https://github.com/snoonan77/security-research/blob/master/CVE-2017-16924Third Party Advisory
- https://www.manageengine.com/desktop-management-msp/password-encryption-policy-violation.htmlThird Party Advisory
- https://github.com/snoonan77/security-research/blob/master/CVE-2017-16924Third Party Advisory
- https://www.manageengine.com/desktop-management-msp/password-encryption-policy-violation.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.