CVE-2022-47578 describes a bypass vulnerability in Zoho ManageEngine Device Control Plus 10.1.2228.15, allowing USB restriction circumvention by booting into Safe Mode. This high-severity flaw (CVSS 7.8) enables local attackers with low privileges to exfiltrate data or introduce malware, as the endpoint protection agent fails to enforce USB controls in Safe Mode. Despite the vendor's denial, this vulnerability presents a significant risk for data loss or system compromise. Currently, there is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.1.2228.15CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_device_control_plus:10.1.2228.15:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.