Authentication Bypass in Zoho ManageEngine Suite Products
CVE-2020-24786

9.8CRITICAL

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
31 August 2020

What is CVE-2020-24786?

An authentication bypass vulnerability has been identified in various Zoho ManageEngine products. The issue arises from a remotely accessible Java servlet, which allows unauthorized modification of system integration properties, potentially leading to a complete compromise of the ManageEngine suite. This could expose organizations to significant security risks, making it critical for users to update their applications to the latest build versions as soon as possible to mitigate the risk.

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.