CVE-2023-29505
MEDIUMManageEngine Network Configuration Manager 12.6.165 - Cross-site WebSocket Hijacking via WebSocket Endpoint
Title source: llmDescription
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
References (4)
Core 4
Core References
Various Sources
https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-29505
Third Party Advisory
https://excellium-services.com/cert-xlm-advisory/CVE-2023-29505
Release Notes
https://www.manageengine.com/network-monitoring/help/read-me-complete.html#build_127131
Vendor Advisory
https://www.manageengine.com/itom/advisory/cve-2023-29505.html
Scores
CVSS v3
4.3
EPSS
0.0089
EPSS Percentile
54.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-346
Status
published
Products (1)
zohocorp/manageengine_network_configuration_manager
12.6 build126165
Published
Aug 04, 2023
Tracked Since
Feb 18, 2026