CVE-2023-6105 is an information disclosure vulnerability affecting multiple ManageEngine products on Linux and Microsoft platforms. A low-privileged operating system user can exploit this to expose encryption keys, which can then be used to decrypt product database passwords. This allows unauthorized access to the ManageEngine product database. Rated with a CVSS score of 5.5 (Medium), the vulnerability requires local access to the host (AV:L) but has low attack complexity (AC:L) and no user interaction (UI:N). The primary impact is high confidentiality compromise (C:H), as database passwords can be revealed. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_analytics_plus:*:*:*:*:*:*:*:* | ||
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_appcreator:*:*:*:*:*:*:*:* | ||
< 11.2.2328.01CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_application_control_plus:*:*:*:*:*:*:*:* | ||
< 11.2.2328.01CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_browser_security_plus:*:*:*:*:*:*:*:* | ||
< 11.2.2328.01CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_device_control_plus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.