CVE-2025-11670

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable toNTLM Hash Exposure.
This vulnerability is exploitable only by technicians who have the Impersonate as Admin option enabled.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
ZohocorpCNA
6.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
zohocorpmanageengine_admanager_plus
𝑥
< 8.0
zohocorpmanageengine_admanager_plus
8.0:8000
zohocorpmanageengine_admanager_plus
8.0:8001
zohocorpmanageengine_admanager_plus
8.0:8002
zohocorpmanageengine_admanager_plus
8.0:8010
zohocorpmanageengine_admanager_plus
8.0:8011
zohocorpmanageengine_admanager_plus
8.0:8012
zohocorpmanageengine_admanager_plus
8.0:8020
zohocorpmanageengine_admanager_plus
8.0:8021
zohocorpmanageengine_admanager_plus
8.0:8022
𝑥
= Vulnerable software versions