Manageengine Application Control Plus
Vendor:
First CVE: Sep 30, 2020 · Active for 5 years
4
Total CVEs
More Total CVEs than 75% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
25.0%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Manageengine Application Control Plus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2020
5 years ago
Most Recent CVE
Nov 15, 2023
986 days ago
CVE Severity & Scoring
Manageengine Application Control Plus4 CVEs
75%
25%
All CVEs352,785 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local1 (25.0%)
Network3 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (75.0%)
High0 (0.0%)
None1 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47966CRITICAL Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java | Jan 18, 2023 | 9.8 | 99 | YES | YES |
CVE-2023-6105MEDIUM An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host | Nov 15, 2023 | 5.5 | 17 | NO | NO |
CVE-2020-15595MEDIUM An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed | Sep 30, 2020 | 4.3 | 14 | NO | NO |
CVE-2020-15594MEDIUM An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to disco | Sep 30, 2020 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
1 CVE
25.0% of CVEs· 99th percentile
Metasploit
1 CVE
25.0% of CVEs· 98th percentile
Nuclei
1 CVE
25.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Manageengine Application Control Plus
Top CWEs
Versions
No cataloged versions.