Impact
An authenticated user with low privileges can exploit a broken access control flaw to create alert notifications for firewalls not within their assigned scope. This grants the user elevated visibility and influence over firewall alert mechanisms, potentially enabling privacy violations, alert fatigue, or discovery of network boundaries.
Affected Systems
The vulnerability affects ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and earlier. Updated releases that remove the flaw are available for both products.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact. EPSS information is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that while the flaw is serious, public exploitation evidence is not yet documented. The attack requires prior authentication, so the most plausible vector involves a legitimate, low‑privileged account being used to trigger the unauthorized alert creation.
OpenCVE Enrichment