Hardcoded Credentials Vulnerability in Zoho ManageEngine Remote Access Plus
CVE-2021-41827
7.5HIGH
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 30 September 2021
What is CVE-2021-41827?
Zoho ManageEngine Remote Access Plus versions prior to 10.1.2121.1 expose a security risk due to hardcoded credentials embedded in the source code. These credentials, intended for read-only access, can potentially allow unauthorized individuals to access sensitive data within the application. This issue stems from the DCBackupRestore JAR archive, raising serious concerns about the security measures in place for protecting user information. It is critical for organizations using this software to update to the latest version to mitigate this vulnerability.
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved