CVE-2018-11716: Zohocorp ManageEngine Desktop Central

Critical severity, CVSS 9.8. EPSS: 14.3% chance of exploitation in the next 30 days.

An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.

Affected products

  • Zohocorp ManageEngine Desktop Central: before 100230 (fixed in 100230)

Published 2018-07-16. Last modified 2026-06-17.