Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-8838


An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack.


Published

2020-03-23T17:15:15.427

Last Modified

2024-11-21T05:39:32.317

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.4 (MEDIUM)

CVSSv2 Vector

AV:A/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

4.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-354

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zohocorp manageengine_assetexplorer 6.5 Yes

References