CVE-2017-16924

CRITICAL

ManageEngine Desktop Central MSP <10.0.137 - Info Disclosure

Title source: llm
STIX 2.1

Description

Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys. This is fixed in build 100157.

Scores

CVSS v3 9.8
EPSS 0.0173
EPSS Percentile 82.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-330
Status published
Products (1)
zohocorp/manageengine_desktop_central 10.0.137
Published Feb 19, 2018
Tracked Since Feb 18, 2026