VulnerabilityModified
CVE-2022-26653
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
MEDIUM 5.3EPSS 2.12%
Does this matter?
Lower severity and a low EPSS score (2.12%). Track it; it rarely justifies an emergency change on its own.
Description
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.12% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-425
- Affected
- zohocorp/manageengine remote access plus
- Source
- cve@mitre.org
References
- https://raxis.com/blog/cve-2022-26653-and-cve-2022-26777Exploit, Third Party Advisory
- https://www.manageengine.com/remote-desktop-management/advisory/cve-2022-26653.htmlVendor Advisory
- https://raxis.com/blog/cve-2022-26653-and-cve-2022-26777Exploit, Third Party Advisory
- https://www.manageengine.com/remote-desktop-management/advisory/cve-2022-26653.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.