Zohocorp Manageengine Desktop Central vulnerabilities

47 known vulnerabilities affecting zohocorp/manageengine_desktop_central.

Total CVEs
47
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH18MEDIUM11

Vulnerabilities

Page 1 of 3
CVE-2023-4769HIGHCVSS 8.8v9.1.02023-11-03
CVE-2023-4769 [MEDIUM] CWE-918 CVE-2023-4769: A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifi A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.
nvd
CVE-2023-4768MEDIUMCVSS 6.1v9.1.02023-11-03
CVE-2023-4768 [MEDIUM] CWE-93 CVE-2023-4768: A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1. A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.
nvd
CVE-2023-4767MEDIUMCVSS 6.1v9.1.02023-11-03
CVE-2023-4767 [MEDIUM] CWE-93 CVE-2023-4767: A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1. A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.
nvd
CVE-2022-48362HIGHCVSS 8.8fixed in 10.1.2137.22023-02-25
CVE-2022-48362 [HIGH] CVE-2022-48362: Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory travers Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)
nvd
CVE-2022-23779MEDIUMCVSS 5.3PoCfixed in 10.1.2137.82022-03-02
CVE-2022-23779 [MEDIUM] CWE-200 CVE-2022-23779: Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. Th Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.
nvd
CVE-2022-23863MEDIUMCVSS 6.5fixed in 10.1.2137.102022-01-28
CVE-2022-23863 [MEDIUM] CVE-2022-23863: Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any use Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
nvd
CVE-2021-44757CRITICALCVSS 9.1fixed in 10.1.2137.92022-01-18
CVE-2021-44757 [CRITICAL] CVE-2021-44757: Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allo Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
nvd
CVE-2021-46164HIGHCVSS 8.8fixed in 10.0.6622022-01-10
CVE-2021-46164 [HIGH] CVE-2021-46164: Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated u Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
nvd
CVE-2021-46165HIGHCVSS 7.8fixed in 10.0.6622022-01-10
CVE-2021-46165 [HIGH] CVE-2021-46165: Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.
nvd
CVE-2021-46166MEDIUMCVSS 6.5fixed in 10.0.6622022-01-10
CVE-2021-46166 [MEDIUM] CWE-200 CVE-2021-46166: Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive inf Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
nvd
CVE-2021-44515CRITICALCVSS 9.8KEVPoCfixed in 10.1.2127.18≥ 10.1.2128.0, < 10.1.2137.32021-12-12
CVE-2021-44515 [CRITICAL] CVE-2021-44515: Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code exe Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier,
nvd
CVE-2021-37414HIGHCVSS 7.5fixed in 10.0.7092021-09-10
CVE-2021-37414 [HIGH] CWE-287 CVE-2021-37414: Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
nvd
CVE-2020-9367HIGHCVSS 7.8v10.0.4862021-03-18
CVE-2020-9367 [HIGH] CWE-427 CVE-2020-9367: The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code, l
nvd
CVE-2020-28050CRITICALCVSS 9.1fixed in 10.0.6472021-03-05
CVE-2020-28050 [CRITICAL] CWE-287 CVE-2020-28050: Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from m Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.
nvd
CVE-2019-16962MEDIUMCVSS 5.4v10.0.4302021-01-06
CVE-2019-16962 [MEDIUM] CWE-79 CVE-2019-16962: Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
nvd
CVE-2020-24397HIGHCVSS 7.2v10.0.02020-10-02
CVE-2020-24397 [HIGH] CWE-190 CVE-2020-24397: An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An at An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges.
nvd
CVE-2020-15589HIGHCVSS 8.1v10.0.552.w2020-10-02
CVE-2020-15589 [HIGH] CVE-2020-15589: A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendReq A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus before 10.1.2119.1. By exploiting this issue, an attacker-controlled server can force the client to skip TLS certificate validation, leading to a man-in-the-
nvd
CVE-2020-15588CRITICALCVSS 9.8fixed in 10.0.5612020-07-29
CVE-2020-15588 [CRITICAL] CWE-190 CVE-2020-15588: An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attac An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. This issue will occur only when untrusted co
nvd
CVE-2020-10859MEDIUMCVSS 6.5fixed in 10.0.4842020-05-05
CVE-2020-10859 [MEDIUM] CWE-22 CVE-2020-10859: Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.
nvd
CVE-2020-8509HIGHCVSS 7.5fixed in 10.0.4832020-03-30
CVE-2020-8509 [HIGH] CWE-306 CVE-2020-8509: Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerati Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
nvd