CyberRota Analysis
AI-GeneratedZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and earlier are susceptible to a Broken Access Control vulnerability, enabling authenticated low-privilege users to alter Change Management report schedule configurations for firewalls beyond their designated scope. This flaw poses a significant risk as it could lead to unauthorized changes in firewall management, potentially compromising network security. Organizations utilizing these affected versions should prioritize immediate remediation to mitigate the risk of unauthorized access and configuration changes.
Original NVD Description
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.