VYPR
Unrated severityNVD Advisory· Published Mar 5, 2021· Updated Aug 4, 2024

CVE-2020-28050

CVE-2020-28050

Description

Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zoho ManageEngine Desktop Central before build 10.0.647 used a single authentication token for all agents, allowing any agent to impersonate another.

Vulnerability

In Zoho ManageEngine Desktop Central builds prior to 10.0.647, the authentication mechanism between agents and the server used a single shared token per instance rather than unique credentials per agent ([1], [2]). This flaw allowed any agent possessing the global token to communicate with the server as if it were any other agent, without proper individual authentication.

Exploitation

An attacker who controls or compromises any agent enrolled in a Desktop Central instance can leverage the shared token to impersonate other agents. No additional authentication or user interaction is required beyond having access to the token from an existing agent. The attacker can then send arbitrary data to the server under the identity of another agent.

Impact

Successful exploitation enables the attacker to submit unauthorized agent data to the server, potentially leading to improper authorization handling. This could result in data corruption, privilege escalation, or further compromise of the managed endpoints, depending on the server's trust in agent data.

Mitigation

The vulnerability is fixed in Desktop Central build 10.0.647 (also known as Endpoint Central build 100647) ([1], [2]). Customers must upgrade to this build or later and then enable Client Certificate Authentication via Admin > Security and Privacy > Security Settings > Enable Client Certificate Authentication. This vulnerability is not applicable to cloud editions of the product.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.