CVE Feed

    Dashboard / CVE / CVE-2022-36923

    CVE-2022-36923

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

    Published:Aug 10, 2022
    Last Modified:Sep 24, 2025
    EPS:Aug 10, 2022
    EPSS Score:0.00696
    CVSS Score:5.4

    Affected Products

    Vendor
    Zohocorp
    Product
    Manageengine Firewall Analyzer
    Vendor
    Zohocorp
    Product
    Manageengine Netflow Analyzer
    Vendor
    Zohocorp
    Product
    Manageengine Network Configuration Manager
    Vendor
    Zohocorp
    Product
    Manageengine Opmanager
    Vendor
    Zohocorp
    Product
    Manageengine Opmanager Msp
    Vendor
    Zohocorp
    Product
    Manageengine Opmanager Plus
    Vendor
    Zohocorp
    Product
    Manageengine Oputils

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High