VYPR

ManageEngine Network Configuration Manager

by Zoho

CVEs (9)

  • CVE-2021-41081CriNov 11, 2021
    risk 0.69cvss 9.8epss 0.63

    Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.

  • CVE-2021-43319CriNov 30, 2021
    risk 0.65cvss 9.8epss 0.21

    Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.

  • CVE-2021-41080CriNov 11, 2021
    risk 0.64cvss 9.8epss 0.04

    Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.

  • CVE-2022-37024HigAug 10, 2022
    risk 0.63cvss 8.8epss 0.79

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code…

  • CVE-2018-18980HigNov 6, 2018
    risk 0.51cvss 7.5epss 0.25

    An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local…

  • CVE-2022-36923HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.07

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and…

  • CVE-2018-12997HigJun 29, 2018
    risk 0.49cvss 7.5epss 0.07

    Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers…

  • CVE-2018-12998MedJun 29, 2018
    risk 0.48cvss 6.1epss 0.99

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote…

  • CVE-2023-29505MedAug 4, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.