Lucene search

K
cve[email protected]CVE-2023-2291
HistoryApr 26, 2023 - 9:15 p.m.

CVE-2023-2291

2023-04-2621:15:09
web.nvd.nist.gov
15
cve-2023-2291
static credentials
postgresql
manageengine access manager plus
manageengine password manager pro
manageengine pam360
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.9%

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.

Affected configurations

NVD
Node
zohocorpmanageengine_access_manager_plusMatch4.3build4309
OR
zohocorpmanageengine_pam360
OR
zohocorpmanageengine_password_manager_pro

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Zoho ManageEngine Multiple Products",
    "versions": [
      {
        "version": "All",
        "status": "affected"
      }
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.9%

Related for CVE-2023-2291