CVE-2019-20474
Description
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the localhost or the hosts on the same network segment, aka SSRF.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2019-20474: Authentication bypass in Zoho ManageEngine Remote Access Plus 10.0.447 allows guest users to perform SSRF via mail-server test endpoint.
Vulnerability
An authorization bypass vulnerability exists in Zoho ManageEngine Remote Access Plus version 10.0.447. The service endpoint used to test mail-server configuration does not properly enforce access controls, allowing users with the Guest role (read-only access) to reach and abuse the function. This enables a Server-Side Request Forgery (SSRF) condition against the localhost or other hosts on the same network segment [1][2].
Exploitation
An attacker needs only a valid Guest-level account on the Remote Access Plus server. No elevated privileges are required. By sending crafted requests to the vulnerable mail-server test functionality, the attacker can force the server to initiate connections to arbitrary internal IP addresses and ports, effectively performing network and port scans on localhost or adjacent hosts [1][2].
Impact
Successful exploitation allows an attacker with read-only Guest privileges to perform internal network reconnaissance via SSRF. The attacker can enumerate live hosts and open ports on the local network, potentially discovering other vulnerable services. While the vulnerability does not directly lead to arbitrary code execution or data exfiltration, it lowers the barrier for further lateral movement [1][2].
Mitigation
The vulnerability is fixed in Remote Access Plus build 100450, released on 24 January 2020 for on-premises deployments. For cloud deployments, the fix was released on 29 September 2020. Administrators should update to the latest build available on the ManageEngine service packs page. No workarounds have been documented [2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho ManageEngine/Remote Access Plusdescription
- Range: = 10.0.447
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- excellium-services.com/cert-xlm-advisory/cve-2019-20474/mitrex_refsource_MISC
- www.manageengine.com/remote-desktop-management/knowledge-base/authorization-failure.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.