// For flags

CVE-2020-13154

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.

Zoho ManageEngine Service Plus versiones anteriores a 11.1 build 11112, permite a usuarios autenticados con pocos privilegios detectar la contraseƱa de File Protection mediante una llamada de getFileProtectionSettings a AjaxServlet.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-05-18 CVE Reserved
  • 2020-05-18 CVE Published
  • 2023-04-10 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-862: Missing Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
-
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11100
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11101
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11102
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11103
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11104
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11105
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11106
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11107
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11108
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11109
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11110
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Servicedesk Plus
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus"
11.1
Search vendor "Zohocorp" for product "Manageengine Servicedesk Plus" and version "11.1"
11111
Affected