CVE-2020-15595
The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently obtain information…
Does this matter?
Lower severity and a low EPSS score (2.21%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently obtain information about the cartography of the internal networks to which the product has access.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- zohocorp/manageengine application control plus
- Source
- cve@mitre.org
References
- https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-15595
- https://excellium-services.com/cert-xlm-advisory/CVE-2020-15595Exploit, Third Party Advisory
- https://excellium-services.com/cert-xlm-advisory/CVE-2020-15595Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.