CVE-2019-20474
Zoho ManageEngine Remote Access Plus vulnerability analysis and mitigation

Overview

CVE-2019-20474 affects Zoho ManageEngine Remote Access Plus version 10.0.447. The vulnerability was discovered on October 21, 2019, and involves an authorization issue in the mail-server configuration testing service. This security flaw allows users with 'Guest' privileges (read-only access) to perform unauthorized actions (ManageEngine KB, Excellium Services).

Technical details

The vulnerability has a CVSS v3.1 score of 4.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N), indicating a relatively moderate severity level. The issue specifically affects the mail server configuration testing service, where improper authorization controls allow guest users to exceed their intended read-only access permissions (Excellium Services).

Impact

The vulnerability allows guest users to access unauthorized functionality, including the ability to perform network and port scans of the localhost or hosts on the same network segment. Additionally, affected users could access credential manager details such as credential name, credential type, username, and domain/workgroup name, though passwords remain protected (ManageEngine KB).

Mitigation and workarounds

The vulnerability was fixed in Remote Access Plus version 10.0.451. For on-premises installations, users should download and apply the latest Remote Access Plus build from the service packs page. For cloud installations, the fix was released on September 29, 2020 (ManageEngine KB).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine Remote Access Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-47966CRITICAL9.8
  • Zoho ManageEngine ServiceDesk PlusZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:application_control_plus
YesYesJan 18, 2023
CVE-2021-42955HIGH7.8
  • Zoho ManageEngine Remote Access PlusZoho ManageEngine Remote Access Plus
  • cpe:2.3:a:zohocorp:manageengine_remote_access_plus
NoYesNov 17, 2021
CVE-2023-6105MEDIUM5.5
  • Zoho ManageEngine ServiceDesk PlusZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:manageengine_servicedesk_plus
NoYesNov 15, 2023
CVE-2022-26777MEDIUM5.3
  • Zoho ManageEngine Remote Access PlusZoho ManageEngine Remote Access Plus
  • cpe:2.3:a:zohocorp:manageengine_remote_access_plus
NoYesApr 16, 2022
CVE-2022-26653MEDIUM5.3
  • Zoho ManageEngine Remote Access PlusZoho ManageEngine Remote Access Plus
  • cpe:2.3:a:zohocorp:manageengine_remote_access_plus
NoYesApr 16, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management