CVE-2023-29505: Zohocorp ManageEngine Network Configuration Manager

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

Affected products

  • Zohocorp ManageEngine Network Configuration Manager: version 12.6 only

Published 2023-08-04. Last modified 2026-06-17.