CVE-2022-26653

Severity
5.3MEDIUM
EPSS
2.1%
top 16.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateApr 17

Description

Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-r527-qppg-g2jq: Zoho ManageEngine Remote Access Plus before 102022-04-17
CVEList
CVE-2022-26653: Zoho ManageEngine Remote Access Plus before 102022-04-16
CVE-2022-26653 (MEDIUM CVSS 5.3) | Zoho ManageEngine Remote Access Plu | cvebase.io