PT-2022-28076 · Zoho · Zoho Manageengine Device Control Plus

Published

2022-12-20

·

Updated

2024-08-03

·

CVE-2022-47578

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Device Control Plus version 10.1.2228.15
Description An issue was discovered in the endpoint protection agent, where configuring complete restrictions on USB devices does not prevent bypassing these restrictions by booting into Safe Mode. This allows a file to be exchanged outside the system and potentially introduces malware. Data exfiltration can occur. The vendor disputes this as a vulnerability in their product.
Recommendations For Zoho ManageEngine Device Control Plus version 10.1.2228.15, consider restricting access to Safe Mode to prevent bypassing USB restrictions, as a temporary workaround until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2022-47578

Affected Products

Zoho Manageengine Device Control Plus