Unrated severityNVD Advisory· Published Sep 4, 2014· Updated Jun 17, 2026
CVE-2014-5377
CVE-2014-5377
Description
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:manageengine:device_expert:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:manageengine:device_expert:*:*:*:*:*:*:*:*range: <=5.9
- (no CPE)range: <5.9 build 5981
Patches
Vulnerability mechanics
References
10- www.manageengine.com/products/device-expert/release-notes.htmlnvdPatch
- packetstormsecurity.com/files/128019/ManageEngine-DeviceExpert-5.9-Credential-Disclosure.htmlnvdExploit
- seclists.org/fulldisclosure/2014/Aug/76nvdExploit
- www.exploit-db.com/exploits/34449nvdExploit
- raw.githubusercontent.com/pedrib/PoC/master/me_deviceexpert-5.txtnvdExploit
- seclists.org/fulldisclosure/2014/Aug/75nvd
- seclists.org/fulldisclosure/2014/Aug/84nvd
- www.securityfocus.com/archive/1/533250/100/0/threadednvd
- www.securityfocus.com/bid/69443nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/95562nvd
News mentions
0No linked articles in our index yet.