CVE-2020-14048
HIGHZohocorp Manageengine Servicedesk Plus - Missing Authentication
Title source: ruleDescription
Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.2501
EPSS Percentile
96.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-306
Status
published
Products (2)
zohocorp/manageengine_servicedesk_plus
8.2 (18 CPE variants)
zohocorp/manageengine_servicedesk_plus
9.0 (32 CPE variants)
Published
Jun 12, 2020
Tracked Since
Feb 18, 2026