Impact
The vulnerability allows an attacker to read data that should be kept confidential. The problem lies in the Firewall Analyzer syslog collector, which exposes log information to unauthorized users. This is a classic information disclosure weakness that could expose system configuration details and other sensitive data, potentially enabling further attacks, but the description does not mention remote code execution or other escalation.
Affected Systems
The affected products are ZohoCorp ManageEngine Firewall Analyzer and ManageEngine OpManager, specifically all releases up to and including version 12.8.709. Users running these older versions should verify their software version and plan an upgrade.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity, classifying the vulnerability as a High Impact. Because the EPSS score is not available, the current probability of exploitation cannot be quantified, though the absence of a KEV listing suggests no actively known exploits. The likely attack vector involves accessing the syslog collector from an authenticated or vulnerable network connection, which may require an attacker to have network access to the monitoring infrastructure or possess credentials allowing such access. The vulnerability's impact is limited to data exposure; there is no evidence of further privilege escalation in the provided description.
OpenCVE Enrichment