Impact
The vulnerability is a broken access control flaw (CWE‑639) in ManageEngine OpManager and Firewall Analyzer that permits an authenticated user with low privileges to alter change‑management report schedule settings for firewalls that are outside their assigned scope. This capability can distort or delete reporting data, potentially masking malicious activity or affecting compliance.
Affected Systems
Affected products include Zohocorp's ManageEngine Firewall Analyzer and OpManager. Versions 12.8.710 and earlier are impacted. The flaw resides in the web‑based administration consoles of both applications, as identified in the vendor advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential for damage, and because only a low‑privilege authenticated account is required, a compromised user could exploit the flaw. No EPSS data is available, and the vulnerability is not listed in KEV, suggesting that large‑scale exploitation has not yet been observed but remains possible. Based on the description, it is inferred that attackers would most likely trigger the issue via the web UI, submitting crafted requests that modify report schedules; until a patch is applied, the risk is moderate to high.
OpenCVE Enrichment