CVE-2024-36036

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.2 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
ManageEngineCNA
4.2 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
VendorProductVersion
zohocorpmanageengine_adaudit_plus
𝑥
< 7.2
zohocorpmanageengine_adaudit_plus
7.2:7200
zohocorpmanageengine_adaudit_plus
7.2:7201
zohocorpmanageengine_adaudit_plus
7.2:7202
zohocorpmanageengine_adaudit_plus
7.2:7203
zohocorpmanageengine_adaudit_plus
7.2:7210
zohocorpmanageengine_adaudit_plus
7.2:7211
zohocorpmanageengine_adaudit_plus
7.2:7212
zohocorpmanageengine_adaudit_plus
7.2:7213
zohocorpmanageengine_adaudit_plus
7.2:7215
zohocorpmanageengine_adaudit_plus
7.2:7220
zohocorpmanageengine_adaudit_plus
7.2:7250
zohocorpmanageengine_adaudit_plus
7.2:7251
zohocorpmanageengine_adaudit_plus
7.2:7260
𝑥
= Vulnerable software versions