Impact
The vulnerability allows an authenticated user with low privileges to gain Administrator rights by importing a Report Profile into ManageEngine OpManager or Firewall Analyzer. This is a classic case of improper privilege enforcement, classified as CWE-250. The attacker can thus perform actions normally reserved for administrators, such as modifying configurations, viewing sensitive data, or launching further attacks against the network.
Affected Systems
ZooCorp’s ManageEngine OpManager and Firewall Analyzer products, specifically versions 12.8.710 and older, are affected. Users of these applications should verify the installed version against the list of vulnerable releases.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated local or remote user who can use the Report Profile import feature. To exploit it, an attacker simply needs an account with read‑only or other low‑level privileges that still has access to the import function, which is then abused to elevate to full administrator status. The absence of mitigation restrictions makes exploitation straightforward for anyone who satisfies this minimal prerequisite.
OpenCVE Enrichment