CVE-2023-41344: Ncsist Mobile Device Manager

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

Affected products

  • Ncsist Mobile Device Manager: version 1.4 only

Published 2023-11-03. Last modified 2026-06-17.