Impact
The vulnerability in Zohocorp ManageEngine Endpoint Central allows the transmission of sensitive data in cleartext for all affected versions, potentially exposing confidential information to anyone who can observe network traffic. This flaw is classified under CWE‑319 and results in a confidentiality breach, with no stated impact on integrity or availability.
Affected Systems
Zohocorp ManageEngine Endpoint Central, all releases prior to 11.4.2528.34.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based; an adversary monitoring traffic between a client and the Endpoint Central server could capture the transmitted data. No privileged access is required, and the primary consequence is the loss of confidentiality.
OpenCVE Enrichment