Manageengine Browser Security Plus
Vendor:
First CVE: Jun 18, 2019 · Active for 7 years
3
Total CVEs
More Total CVEs than 68% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
33.3%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Manageengine Browser Security Plus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2019
7 years ago
Most Recent CVE
Nov 15, 2023
986 days ago
CVE Severity & Scoring
Manageengine Browser Security Plus3 CVEs
33%
33%
33%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (66.7%)
Network1 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (66.7%)
High0 (0.0%)
None1 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47966CRITICAL Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java | Jan 18, 2023 | 9.8 | 99 | YES | YES |
CVE-2019-12133HIGH Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, t | Jun 18, 2019 | 7.8 | 24 | NO | NO |
CVE-2023-6105MEDIUM An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host | Nov 15, 2023 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (3 CVEs).
CISA KEV
1 CVE
33.3% of CVEs· 99th percentile
Metasploit
1 CVE
33.3% of CVEs· 98th percentile
Nuclei
1 CVE
33.3% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (3 CVEs).
Media Mentions
Signals from CVEs in this product scope (3 CVEs).
Top CNAs Publishing CVEs For Manageengine Browser Security Plus
Top CWEs
Versions
No cataloged versions.