Lucene search

K
cveMitreCVE-2022-24446
HistoryMar 01, 2022 - 2:15 a.m.

CVE-2022-24446

2022-03-0102:15:07
mitre
web.nvd.nist.gov
67
cve-2022-24446
zoho manageengine
key manager plus
unauthorized access
ssh servers
user information
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

32.5%

An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.

Affected configurations

Nvd
Node
zohocorpmanageengine_key_manager_plusMatch6.1.6
OR
zohocorpmanageengine_key_manager_plusMatch6.1.6build6100
OR
zohocorpmanageengine_key_manager_plusMatch6.1.6build6150
OR
zohocorpmanageengine_key_manager_plusMatch6.1.6build6151
OR
zohocorpmanageengine_key_manager_plusMatch6.1.6build6160
OR
zohocorpmanageengine_key_manager_plusMatch6.1.6build6161
VendorProductVersionCPE
zohocorpmanageengine_key_manager_plus6.1.6cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:*:*:*:*:*:*:*
zohocorpmanageengine_key_manager_plus6.1.6cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6100:*:*:*:*:*:*
zohocorpmanageengine_key_manager_plus6.1.6cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6150:*:*:*:*:*:*
zohocorpmanageengine_key_manager_plus6.1.6cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6151:*:*:*:*:*:*
zohocorpmanageengine_key_manager_plus6.1.6cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6160:*:*:*:*:*:*
zohocorpmanageengine_key_manager_plus6.1.6cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6161:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

32.5%

Related for CVE-2022-24446