SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-15595

The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently obtain information…

MEDIUM 4.3EPSS 2.21%

Does this matter?

Lower severity and a low EPSS score (2.21%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently obtain information about the cartography of the internal networks to which the product has access.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
2.21% probability · 82th percentile
CISA KEV
Not listed
Affected
zohocorp/manageengine application control plus
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.