CVE-2024-36037

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ManageEngineCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
zohocorpmanageengine_adaudit_plus
𝑥
< 7.2
zohocorpmanageengine_adaudit_plus
7.2:7200
zohocorpmanageengine_adaudit_plus
7.2:7201
zohocorpmanageengine_adaudit_plus
7.2:7202
zohocorpmanageengine_adaudit_plus
7.2:7203
zohocorpmanageengine_adaudit_plus
7.2:7210
zohocorpmanageengine_adaudit_plus
7.2:7211
zohocorpmanageengine_adaudit_plus
7.2:7212
zohocorpmanageengine_adaudit_plus
7.2:7213
zohocorpmanageengine_adaudit_plus
7.2:7215
zohocorpmanageengine_adaudit_plus
7.2:7220
zohocorpmanageengine_adaudit_plus
7.2:7250
zohocorpmanageengine_adaudit_plus
7.2:7251
zohocorpmanageengine_adaudit_plus
7.2:7260
𝑥
= Vulnerable software versions