VYPR
Unrated severityNVD Advisory· Published Jan 31, 2020· Updated May 30, 2025

CVE-2020-8422

CVE-2020-8422

Description

An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description (but not the password).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zoho ManageEngine Remote Access Plus before 10.0.450 allows Guest users to view credential metadata (names, usernames, domains) of remote machines.

Vulnerability

An authorization issue exists in the Credential Manager feature of Zoho ManageEngine Remote Access Plus versions before 10.0.450. Specifically, a user with the Guest role can enumerate all defined credentials for remote machines, retrieving the credential name, credential type, user name, domain/workgroup name, and description. The actual password is not disclosed. Affected versions include up to 10.0.447 [3].

Exploitation

An attacker must have network access to the Remote Access Plus server and a valid Guest account (which may be the default account or obtained through other means). No further authentication or interaction is required. The attacker can simply navigate to the Credential Manager interface or API to list the credential metadata [3].

Impact

Successful exploitation yields sensitive configuration information about remote machine credentials, including usernames and domain associations. This information can be used to facilitate targeted attacks against the managed systems. The confidentiality impact is rated Low (CVSS 4.3) [3].

Mitigation

The vulnerability is fixed in version 10.0.450, released in January 2020. Users should upgrade to this version or later. No workarounds are documented [3].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.