Unrated severityNVD Advisory· Published Sep 4, 2014· Updated May 6, 2026
CVE-2014-5377
CVE-2014-5377
Description
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.manageengine.com/products/device-expert/release-notes.htmlnvdPatch
- packetstormsecurity.com/files/128019/ManageEngine-DeviceExpert-5.9-Credential-Disclosure.htmlnvdExploit
- seclists.org/fulldisclosure/2014/Aug/76nvdExploit
- www.exploit-db.com/exploits/34449nvdExploit
- raw.githubusercontent.com/pedrib/PoC/master/me_deviceexpert-5.txtnvdExploit
- seclists.org/fulldisclosure/2014/Aug/75nvd
- seclists.org/fulldisclosure/2014/Aug/84nvd
- www.securityfocus.com/archive/1/533250/100/0/threadednvd
- www.securityfocus.com/bid/69443nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/95562nvd
News mentions
0No linked articles in our index yet.