Description
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
Published: 2023-11-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-58361 An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00064}

epss

{'score': 0.00084}


Thu, 13 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database. An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

Subscriptions

Linux Linux Kernel
Microsoft Windows
Zohocorp Manageengine Access Manager Plus Manageengine Adaudit Plus Manageengine Admanager Plus Manageengine Adselfservice Plus Manageengine Analytics Plus Manageengine Appcreator Manageengine Application Control Plus Manageengine Assetexplorer Manageengine Browser Security Plus Manageengine Cloud Security Plus Manageengine Datasecurity Plus Manageengine Device Control Plus Manageengine Endpoint Central Manageengine Endpoint Central Msp Manageengine Endpoint Dlp Plus Manageengine Exchange Reporter Plus Manageengine Firewall Analyzer Manageengine Log360 Ueba Manageengine M365 Manager Plus Manageengine M365 Security Plus Manageengine Mobile Device Manager Plus Manageengine Netflow Analyzer Manageengine Network Configuration Manager Manageengine Opmanager Manageengine Oputils Manageengine Os Deployer Manageengine Pam360 Manageengine Password Manager Pro Manageengine Patch Connect Plus Manageengine Patch Manager Plus Manageengine Recoverymanager Plus Manageengine Remote Access Plus Manageengine Remote Monitoring And Management Manageengine Secure Gateway Server Manageengine Servicedesk Plus Manageengine Servicedesk Plus Msp Manageengine Sharepoint Manager Plus Manageengine Supportcenter Plus Manageengine Vulnerability Manager Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2025-02-13T17:26:03.759Z

Reserved: 2023-11-13T15:10:28.339Z

Link: CVE-2023-6105

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-15T21:15:08.490

Modified: 2025-02-13T18:16:03.270

Link: CVE-2023-6105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses