ManageEngine Vulnerabilities and Affected Products
Vulnerabilities associated with Desktop Central.
Products
Clear product- ADAudit Plus35 vulnerabilities
- adaudit_plus25 vulnerabilities
- Applications Manager8 vulnerabilities
- Exchange Reporter Plus8 vulnerabilities
- ADSelfService Plus5 vulnerabilities
- OpManager5 vulnerabilities
- Endpoint Central4 vulnerabilities
- ServiceDesk Plus MSP4 vulnerabilities
- Desktop Central3 vulnerabilities
- exchange_reporter_plus3 vulnerabilities
- PAM3603 vulnerabilities
- ServiceDesk Plus3 vulnerabilities
- SupportCenter Plus3 vulnerabilities
- ADManager Plus2 vulnerabilities
- Analytics Plus2 vulnerabilities
- Asset Explorer2 vulnerabilities
- DDI Central2 vulnerabilities
- servicedesk2 vulnerabilities
- Access Manager Plus1 vulnerability
- desktop_central1 vulnerability
- OpManager, OpManager Plus, OpManager MSP, OpManager Enterprise Edition1 vulnerability
- OpManager, Remote Monitoring and Management1 vulnerability
- Password Manager Pro1 vulnerability
- password_manager_pro1 vulnerability
- Service Desk Plus1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-4769MEDIUM | Server-Side Request Forgery in ManageEngine Desktop CentralA SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests. CWE-918Nov 3, 2023 | CVSS6.6v3.1 | EPSS3.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4768MEDIUM | Improper Neutralization of CRLF Sequences in ManageEngine Desktop CentralA CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf. CWE-93Nov 3, 2023 | CVSS6.1v3.1 | EPSS2.87% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4767MEDIUM | Improper Neutralization of CRLF Sequences in ManageEngine Desktop CentralA CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv. | CVSS6.1v3.1 | EPSS2.87% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |