CVE-2018-11716: Zohocorp ManageEngine Desktop Central
Critical severity, CVSS 9.8. EPSS: 14.3% chance of exploitation in the next 30 days.
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.
Affected products
- Zohocorp ManageEngine Desktop Central: before 100230 (fixed in 100230)
Published 2018-07-16. Last modified 2026-06-17.