// For flags

CVE-2022-24447

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

Se ha detectado un problema en Zoho ManageEngine Key Manager Plus versiones anteriores a 6200. Un servicio expuesto por la aplicación permite a un usuario, con el nivel de Operador, acceder a certificados SSL almacenados y a los pares de claves asociados durante la exportación

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-02-04 CVE Reserved
  • 2022-03-02 CVE Published
  • 2024-05-09 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
<= 5.9
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version " <= 5.9"
-
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
6.0
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version "6.0"
6000
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
6.0
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version "6.0"
6001
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
6.0
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version "6.0"
6002
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
6.1
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version "6.1"
6100
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
6.1
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version "6.1"
6150
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
6.1
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version "6.1"
6151
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
6.1
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version "6.1"
6160
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Key Manager Plus
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus"
6.1
Search vendor "Zohocorp" for product "Manageengine Key Manager Plus" and version "6.1"
6161
Affected