Cross-Site WebSocket Hijacking in Zoho ManageEngine Network Configuration Manager
CVE-2023-29505

8.8HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
4 August 2023

What is CVE-2023-29505?

A vulnerability has been identified in the Zoho ManageEngine Network Configuration Manager, specifically version 12.6.165. This flaw involves a weakness in the WebSocket endpoint, which permits attackers to exploit cross-site WebSocket hijacking. By leveraging this vulnerability, unauthorized users may gain access to sensitive communication sessions, posing a significant risk to the security and integrity of network management operations.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.