SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-26600

ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.

MEDIUM 6.5EPSS 6.31%

Does this matter?

Lower severity and a low EPSS score (6.31%). Track it; it rarely justifies an emergency change on its own.

Description

ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
6.31% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
zohocorp/manageengine assetexplorer · zohocorp/manageengine servicedesk plus · zohocorp/manageengine servicedesk plus msp · zohocorp/manageengine supportcenter plus
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.