CVE-2020-8422
Description
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description (but not the password).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zoho ManageEngine Remote Access Plus before 10.0.450 allows Guest users to view credential metadata (names, usernames, domains) of remote machines.
Vulnerability
An authorization issue exists in the Credential Manager feature of Zoho ManageEngine Remote Access Plus versions before 10.0.450. Specifically, a user with the Guest role can enumerate all defined credentials for remote machines, retrieving the credential name, credential type, user name, domain/workgroup name, and description. The actual password is not disclosed. Affected versions include up to 10.0.447 [3].
Exploitation
An attacker must have network access to the Remote Access Plus server and a valid Guest account (which may be the default account or obtained through other means). No further authentication or interaction is required. The attacker can simply navigate to the Credential Manager interface or API to list the credential metadata [3].
Impact
Successful exploitation yields sensitive configuration information about remote machine credentials, including usernames and domain associations. This information can be used to facilitate targeted attacks against the managed systems. The confidentiality impact is rated Low (CVSS 4.3) [3].
Mitigation
The vulnerability is fixed in version 10.0.450, released in January 2020. Users should upgrade to this version or later. No workarounds are documented [3].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho/ManageEngine Remote Access Plusdescription
- Range: <10.0.450
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.