CVE-2021-31159

Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
zohocorpmanageengine_servicedesk_plus_msp
8.0 ≤
𝑥
≤ 9.4
zohocorpmanageengine_servicedesk_plus_msp
10.5:10500
zohocorpmanageengine_servicedesk_plus_msp
10.5:10501
zohocorpmanageengine_servicedesk_plus_msp
10.5:10502
zohocorpmanageengine_servicedesk_plus_msp
10.5:10503
zohocorpmanageengine_servicedesk_plus_msp
10.5:10504
zohocorpmanageengine_servicedesk_plus_msp
10.5:10505
zohocorpmanageengine_servicedesk_plus_msp
10.5:10506
zohocorpmanageengine_servicedesk_plus_msp
10.5:10507
zohocorpmanageengine_servicedesk_plus_msp
10.5:10508
zohocorpmanageengine_servicedesk_plus_msp
10.5:10509
zohocorpmanageengine_servicedesk_plus_msp
10.5:10510
zohocorpmanageengine_servicedesk_plus_msp
10.5:10511
zohocorpmanageengine_servicedesk_plus_msp
10.5:10512
zohocorpmanageengine_servicedesk_plus_msp
10.5:10513
zohocorpmanageengine_servicedesk_plus_msp
10.5:10514
zohocorpmanageengine_servicedesk_plus_msp
10.5:10515
zohocorpmanageengine_servicedesk_plus_msp
10.5:10516
zohocorpmanageengine_servicedesk_plus_msp
10.5:10517
zohocorpmanageengine_servicedesk_plus_msp
10.5:10518
zohocorpmanageengine_servicedesk_plus_msp
10.5:8000
zohocorpmanageengine_servicedesk_plus_msp
10.5:8001
zohocorpmanageengine_servicedesk_plus_msp
10.5:8002
zohocorpmanageengine_servicedesk_plus_msp
10.5:8003
zohocorpmanageengine_servicedesk_plus_msp
10.5:8004
zohocorpmanageengine_servicedesk_plus_msp
10.5:8100
zohocorpmanageengine_servicedesk_plus_msp
10.5:8101
zohocorpmanageengine_servicedesk_plus_msp
10.5:8102
zohocorpmanageengine_servicedesk_plus_msp
10.5:8103
zohocorpmanageengine_servicedesk_plus_msp
10.5:8104
zohocorpmanageengine_servicedesk_plus_msp
10.5:8105
zohocorpmanageengine_servicedesk_plus_msp
10.5:8200
zohocorpmanageengine_servicedesk_plus_msp
10.5:8201
zohocorpmanageengine_servicedesk_plus_msp
10.5:8202
zohocorpmanageengine_servicedesk_plus_msp
10.5:8203
zohocorpmanageengine_servicedesk_plus_msp
10.5:8204
zohocorpmanageengine_servicedesk_plus_msp
10.5:8205
zohocorpmanageengine_servicedesk_plus_msp
10.5:8206
zohocorpmanageengine_servicedesk_plus_msp
10.5:8207
zohocorpmanageengine_servicedesk_plus_msp
10.5:8208
zohocorpmanageengine_servicedesk_plus_msp
10.5:8209
zohocorpmanageengine_servicedesk_plus_msp
10.5:8210
zohocorpmanageengine_servicedesk_plus_msp
10.5:8211
zohocorpmanageengine_servicedesk_plus_msp
10.5:8300
zohocorpmanageengine_servicedesk_plus_msp
10.5:8301
zohocorpmanageengine_servicedesk_plus_msp
10.5:8302
zohocorpmanageengine_servicedesk_plus_msp
10.5:8303
zohocorpmanageengine_servicedesk_plus_msp
10.5:8304
zohocorpmanageengine_servicedesk_plus_msp
10.5:8305
zohocorpmanageengine_servicedesk_plus_msp
10.5:8306
zohocorpmanageengine_servicedesk_plus_msp
10.5:8307
zohocorpmanageengine_servicedesk_plus_msp
10.5:8308
zohocorpmanageengine_servicedesk_plus_msp
10.5:8309
zohocorpmanageengine_servicedesk_plus_msp
10.5:8310
zohocorpmanageengine_servicedesk_plus_msp
10.5:8311
zohocorpmanageengine_servicedesk_plus_msp
10.5:8312
zohocorpmanageengine_servicedesk_plus_msp
10.5:9000
zohocorpmanageengine_servicedesk_plus_msp
10.5:9001
zohocorpmanageengine_servicedesk_plus_msp
10.5:9002
zohocorpmanageengine_servicedesk_plus_msp
10.5:9003
zohocorpmanageengine_servicedesk_plus_msp
10.5:9004
zohocorpmanageengine_servicedesk_plus_msp
10.5:9005
zohocorpmanageengine_servicedesk_plus_msp
10.5:9006
zohocorpmanageengine_servicedesk_plus_msp
10.5:9007
zohocorpmanageengine_servicedesk_plus_msp
10.5:9008
zohocorpmanageengine_servicedesk_plus_msp
10.5:9009
zohocorpmanageengine_servicedesk_plus_msp
10.5:9201
zohocorpmanageengine_servicedesk_plus_msp
10.5:9203
zohocorpmanageengine_servicedesk_plus_msp
10.5:9204
zohocorpmanageengine_servicedesk_plus_msp
10.5:9205
zohocorpmanageengine_servicedesk_plus_msp
10.5:9206
zohocorpmanageengine_servicedesk_plus_msp
10.5:9207
zohocorpmanageengine_servicedesk_plus_msp
10.5:9208
zohocorpmanageengine_servicedesk_plus_msp
10.5:9209
zohocorpmanageengine_servicedesk_plus_msp
10.5:9210
zohocorpmanageengine_servicedesk_plus_msp
10.5:9300
zohocorpmanageengine_servicedesk_plus_msp
10.5:9301
zohocorpmanageengine_servicedesk_plus_msp
10.5:9302
zohocorpmanageengine_servicedesk_plus_msp
10.5:9303
zohocorpmanageengine_servicedesk_plus_msp
10.5:9304
zohocorpmanageengine_servicedesk_plus_msp
10.5:9305
zohocorpmanageengine_servicedesk_plus_msp
10.5:9306
zohocorpmanageengine_servicedesk_plus_msp
10.5:9307
zohocorpmanageengine_servicedesk_plus_msp
10.5:9308
zohocorpmanageengine_servicedesk_plus_msp
10.5:9400
zohocorpmanageengine_servicedesk_plus_msp
10.5:9401
zohocorpmanageengine_servicedesk_plus_msp
10.5:9402
zohocorpmanageengine_servicedesk_plus_msp
10.5:9403
zohocorpmanageengine_servicedesk_plus_msp
10.5:9404
zohocorpmanageengine_servicedesk_plus_msp
10.5:9405
zohocorpmanageengine_servicedesk_plus_msp
10.5:9406
zohocorpmanageengine_servicedesk_plus_msp
10.5:9407
zohocorpmanageengine_servicedesk_plus_msp
10.5:9408
zohocorpmanageengine_servicedesk_plus_msp
10.5:9409
zohocorpmanageengine_servicedesk_plus_msp
10.5:9410
zohocorpmanageengine_servicedesk_plus_msp
10.5:9411
zohocorpmanageengine_servicedesk_plus_msp
10.5:9412
zohocorpmanageengine_servicedesk_plus_msp
10.5:9413
zohocorpmanageengine_servicedesk_plus_msp
10.5:9414
zohocorpmanageengine_servicedesk_plus_msp
10.5:9415
zohocorpmanageengine_servicedesk_plus_msp
10.5:9416
zohocorpmanageengine_servicedesk_plus_msp
10.5:9417
zohocorpmanageengine_servicedesk_plus_msp
10.5:9418
zohocorpmanageengine_servicedesk_plus_msp
10.5:9419
zohocorpmanageengine_servicedesk_plus_msp
10.5:9420
zohocorpmanageengine_servicedesk_plus_msp
10.5:9421
zohocorpmanageengine_servicedesk_plus_msp
10.5:9422
zohocorpmanageengine_servicedesk_plus_msp
10.5:9423
zohocorpmanageengine_servicedesk_plus_msp
10.5:9424
zohocorpmanageengine_servicedesk_plus_msp
10.5:9425
zohocorpmanageengine_servicedesk_plus_msp
10.5:9426
zohocorpmanageengine_servicedesk_plus_msp
10.5:9427
𝑥
= Vulnerable software versions