PT-2024-20019 · Zoho · Manageengine Desktop Central

Published

2024-03-11

·

Updated

2024-03-20

·

CVE-2024-2370

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions ManageEngine Desktop Central version 9, build 90055
Description A critical flaw in ManageEngine Desktop Central poses a major security risk due to an unrestricted file upload vulnerability. This issue could allow a remote attacker to upload a malicious file to the system without any credentials provided.
Recommendations For ManageEngine Desktop Central version 9, build 90055, consider disabling the file upload feature until a patch is available to prevent exploitation. Restrict access to the system to minimize the risk of malicious file uploads. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2024-2370

Affected Products

Manageengine Desktop Central