A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-54616 A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.
Fixes

Solution

The vulnerability has been fixed in the latest version of Desktop Central.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-05T18:05:51.428Z

Reserved: 2023-09-05T11:46:03.159Z

Link: CVE-2023-4769

cve-icon Vulnrichment

Updated: 2024-08-02T07:38:00.511Z

cve-icon NVD

Status : Modified

Published: 2023-11-03T11:15:08.517

Modified: 2024-11-21T08:35:56.673

Link: CVE-2023-4769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.