CVE-2020-8422: Zohocorp ManageEngine Remote Access Plus

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description (but not the password).

Affected products

  • Zohocorp ManageEngine Remote Access Plus: before 10.0.450 (fixed in 10.0.450)

Published 2020-01-31. Last modified 2026-06-17.