CVE-2016-6602
CRITICALZOHO WebNMS Framework 5.2-5.2 SP1 - Info Disclosure
Title source: llmDescription
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.
Exploits (2)
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/webnms_cred_disclosure.rb
References (9)
Scores
CVSS v3
9.8
EPSS
0.4777
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-327
Status
published
Products (1)
zohocorp/webnms_framework
5.2 (2 CPE variants)
Published
Jan 23, 2017
Tracked Since
Feb 18, 2026