CVE-2020-28050

CRITICAL

ManageEngine Desktop Central < 10.0.647 - Improper Authentication via Shared Agent Secret

Title source: llm
STIX 2.1

Description

Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.

References (2)

Core 2

Scores

CVSS v3 9.1
EPSS 0.0160
EPSS Percentile 81.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-287
Status published
Products (1)
zohocorp/manageengine_desktop_central < 10.0.647
Published Mar 05, 2021
Tracked Since Feb 18, 2026