VulnerabilityModified
CVE-2023-26601
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
HIGH 7.5EPSS 34.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 34.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 34.06% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- zohocorp/manageengine assetexplorer · zohocorp/manageengine servicedesk plus · zohocorp/manageengine servicedesk plus msp · zohocorp/manageengine supportcenter plus
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.