Impact
ManageEngine DataSecurity Plus versions earlier than 6310 contain a flaw that lets agents that have not been properly enrolled send requests without authenticating. This bypass allows attackers to perform actions through the DataSecurity Plus interface that they would normally be denied, potentially leading to unauthorized data access or manipulation. The weakness is a form of improper input validation (CWE‑20).
Affected Systems
The vulnerability affects Zohocorp’s ManageEngine DataSecurity Plus software. All deployments running versions prior to 6310 are impacted. The advisory lists these products under the vendor product name Zohocorp:ManageEngine DataSecurity Plus.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity. The EPSS score of 1% suggests that the probability of exploitation in the wild is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers with network reach to the DataSecurity Plus server can exploit the flaw by tricking an unsupported or non‑enrolled agent into sending crafted requests, thereby bypassing authentication. Based on the description, it is inferred that the attack vector is remote over the network, exploiting the agent communication channel.
OpenCVE Enrichment