CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 14.3% probability of exploitation in the next 30 days. It may be remotely exploitable.
CVE
CVE-2018-11716
Severity
CRITICAL
CVSS
9.8
EPSS
14.29%
Original NVD Description
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.
Related CVEs
Other vulnerabilities affecting the same vendor(s)