Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-2291

25
FAUCET Score

CVE-2023-2291 describes a critical vulnerability in ManageEngine Access Manager Plus (build 4309), Password Manager Pro, and PAM360, where static credentials embedded in the PostgreSQL database allow for privilege escalation. An attacker with low-level access could exploit this to modify configuration data, gaining administrative privileges. With a CVSS score of 7.8 (High), this vulnerability is easily exploitable locally with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
4.3CPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.3:build4309:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_pam360:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.81%
Probability of exploitation in next 30 days
EPSS Percentile
53.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0081 is in the 89th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

jfrogvendor investigatingvia llm_extracted
lfedgevendor investigatingvia llm_extracted
linkacevendor investigatingvia llm_extracted
markusprojectvendor investigatingvia llm_extracted

Vendor Advisories (4)

jfrogllm-jfrog-bf42084ab2a6f2dfHIGH

Zoho ManageEngine Disclosure of Hardcoded Credentials

Apr 25, 2023
lfedgellm-lfedge-2720eb6edc935775HIGH

Zoho ManageEngine Disclosure of Hardcoded Credentials

Apr 25, 2023
markusprojectllm-markusproject-cccd8600d62b1847HIGH

Zoho ManageEngine Disclosure of Hardcoded Credentials

Apr 25, 2023
linkacellm-linkace-011795cc5734a144HIGH

Zoho ManageEngine Disclosure of Hardcoded Credentials

Apr 25, 2023

References

tenable.com / security/research/tra-2023-16
ExploitThird Party Advisory