CVE-2019-20474
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the localhost or the hosts on the same network segment, aka SSRF.
Se detectó un problema en Zoho ManageEngine Remote Access Plus versión 10.0.447. El servicio para probar la configuración del servidor de correo sufre un problema de autorización permitiendo que un usuario con el rol Guest (acceso de solo lectura) lo use y abuse. Uno de los abusos permite llevar a cabo operaciones de escaneo de red y puertos del host local o los hosts en el mismo segmento de red, también se conoce como una vulnerabilidad de tipo SSRF.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-17 CVE Reserved
- 2020-02-17 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://excellium-services.com/cert-xlm-advisory/cve-2019-20474 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.manageengine.com/remote-desktop-management/knowledge-base/authorization-failure.html | 2022-01-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Manageengine Remote Access Plus Search vendor "Zohocorp" for product "Manageengine Remote Access Plus" | 10.0.447 Search vendor "Zohocorp" for product "Manageengine Remote Access Plus" and version "10.0.447" | - |
Affected
|