Authentication Bypass in Zoho ManageEngine Suite Products
CVE-2020-24786
9.8CRITICAL
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 31 August 2020
What is CVE-2020-24786?
An authentication bypass vulnerability has been identified in various Zoho ManageEngine products. The issue arises from a remotely accessible Java servlet, which allows unauthorized modification of system integration properties, potentially leading to a complete compromise of the ManageEngine suite. This could expose organizations to significant security risks, making it critical for users to update their applications to the latest build versions as soon as possible to mitigate the risk.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved