Vulnerability Description
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Desktop Central | 10.0.124 |
Related Weaknesses (CWE)
References
- https://www.manageengine.com/products/desktop-central/elevation-of-privilege-vulThird Party Advisory
- https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabiExploitTechnical DescriptionThird Party Advisory
- https://www.manageengine.com/products/desktop-central/elevation-of-privilege-vulThird Party Advisory
- https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabiExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-5338?
CVE-2018-5338 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
How severe is CVE-2018-5338?
CVE-2018-5338 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-5338?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Desktop Central.