CVE-2017-11512 describes an arbitrary file download vulnerability in ManageEngine ServiceDesk 9.3.9328. This flaw allows an unauthenticated remote attacker to download arbitrary files from the server due to improper restrictions on the 'name' parameter in the 'download-snapshot' URL. With a CVSS score of 7.5 (HIGH), this vulnerability presents a significant risk, enabling high confidentiality impact without requiring user interaction or authentication. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template for this vulnerability exists, and its high EPSS score suggests a greater likelihood of future exploitation compared to most CVEs. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.3.9328CPE matchmatch criteria | cpe:2.3:a:manageengine:servicedesk:9.3.9328:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.