VulnerabilityModified
CVE-2023-31492
Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.
MEDIUM 6.5EPSS 7.90%
Does this matter?
Lower severity and a low EPSS score (7.90%). Track it; it rarely justifies an emergency change on its own.
Description
Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 7.90% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- zohocorp/manageengine admanager plus
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/177091/ManageEngine-ADManager-Plus-Recovery-Password-Disclosure.html
- https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/admanager-recovery-password-disclosure.mdExploit, Third Party Advisory
- https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-31492.htmlVendor Advisory
- http://packetstormsecurity.com/files/177091/ManageEngine-ADManager-Plus-Recovery-Password-Disclosure.html
- https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/admanager-recovery-password-disclosure.mdExploit, Third Party Advisory
- https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-31492.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.