PT-2024-20019 · Zoho · Manageengine Desktop Central
Published
2024-03-11
·
Updated
2024-03-20
·
CVE-2024-2370
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
ManageEngine Desktop Central version 9, build 90055
Description
A critical flaw in ManageEngine Desktop Central poses a major security risk due to an unrestricted file upload vulnerability. This issue could allow a remote attacker to upload a malicious file to the system without any credentials provided.
Recommendations
For ManageEngine Desktop Central version 9, build 90055, consider disabling the file upload feature until a patch is available to prevent exploitation. Restrict access to the system to minimize the risk of malicious file uploads. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Manageengine Desktop Central