Unknown
CVE-2020-24786
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-24786
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- manageengine ad360,
- manageengine ad360 4.2,
- manageengine adaudit plus,
- manageengine adaudit plus 6.0,
- manageengine admanager plus,
- manageengine admanager plus 7.0,
- manageengine adselfservice plus,
- manageengine adselfservice plus 5.8,
- manageengine cloud security plus,
- manageengine cloud security plus 4.1,
- manageengine datasecurity plus,
- manageengine datasecurity plus 6.0,
- manageengine eventlog analyzer,
- manageengine eventlog analyzer 12.1.3,
- manageengine exchange reporter plus,
- manageengine exchange reporter plus 5.5,
- manageengine log360,
- manageengine log360 5.1,
- manageengine o365 manager plus,
- manageengine o365 manager plus 4.3,
- manageengine recovermanager plus,
- manageengine recovermanager plus 6.0
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: