Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.
2021-11-17T13:15:07.317
2024-11-21T06:28:20.040
Modified
CVSSv3.1: 7.3 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zohocorp | manageengine_remote_access_plus | < 10.1.2132 | Yes |
Operating System | microsoft | windows | - | No |