PT-2025-43944 · Zohocorp · Manageengine Endpoint Central

Published

2025-10-27

·

Updated

2025-10-28

·

CVE-2025-11248

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05
Description An authenticated user with access to logs may be able to obtain the sensitive agent token. The issue involves sensitive information logging.
Recommendations Update ZohoCorp ManageEngine Endpoint Central to version 11.4.2528.05 or later.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-11248

Affected Products

Manageengine Endpoint Central