CVE Feed

    Dashboard / CVE / CVE-2023-6105

    CVE-2023-6105

    An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

    Published:Nov 15, 2023
    Last Modified:Feb 13, 2025
    EPS:Nov 15, 2023
    EPSS Score:0.00084
    CVSS Score:5.5

    Affected Products

    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Zohocorp
    Product
    Manageengine Access Manager Plus
    Vendor
    Zohocorp
    Product
    Manageengine Adaudit Plus
    Vendor
    Zohocorp
    Product
    Manageengine Admanager Plus
    Vendor
    Zohocorp
    Product
    Manageengine Adselfservice Plus
    Vendor
    Zohocorp
    Product
    Manageengine Analytics Plus
    Vendor
    Zohocorp
    Product
    Manageengine Appcreator
    Vendor
    Zohocorp
    Product
    Manageengine Application Control Plus
    Vendor
    Zohocorp
    Product
    Manageengine Assetexplorer
    Vendor
    Zohocorp
    Product
    Manageengine Browser Security Plus
    Vendor
    Zohocorp
    Product
    Manageengine Cloud Security Plus
    Vendor
    Zohocorp
    Product
    Manageengine Datasecurity Plus
    Vendor
    Zohocorp
    Product
    Manageengine Device Control Plus
    Vendor
    Zohocorp
    Product
    Manageengine Endpoint Central
    Vendor
    Zohocorp
    Product
    Manageengine Endpoint Central Msp
    Vendor
    Zohocorp
    Product
    Manageengine Endpoint Dlp Plus
    Vendor
    Zohocorp
    Product
    Manageengine Exchange Reporter Plus
    Vendor
    Zohocorp
    Product
    Manageengine Firewall Analyzer
    Vendor
    Zohocorp
    Product
    Manageengine Log360 Ueba
    Vendor
    Zohocorp
    Product
    Manageengine M365 Manager Plus
    Vendor
    Zohocorp
    Product
    Manageengine M365 Security Plus
    Vendor
    Zohocorp
    Product
    Manageengine Mobile Device Manager Plus
    Vendor
    Zohocorp
    Product
    Manageengine Netflow Analyzer
    Vendor
    Zohocorp
    Product
    Manageengine Network Configuration Manager
    Vendor
    Zohocorp
    Product
    Manageengine Opmanager
    Vendor
    Zohocorp
    Product
    Manageengine Oputils
    Vendor
    Zohocorp
    Product
    Manageengine Os Deployer
    Vendor
    Zohocorp
    Product
    Manageengine Pam360
    Vendor
    Zohocorp
    Product
    Manageengine Password Manager Pro
    Vendor
    Zohocorp
    Product
    Manageengine Patch Connect Plus
    Vendor
    Zohocorp
    Product
    Manageengine Patch Manager Plus
    Vendor
    Zohocorp
    Product
    Manageengine Recoverymanager Plus
    Vendor
    Zohocorp
    Product
    Manageengine Remote Access Plus
    Vendor
    Zohocorp
    Product
    Manageengine Remote Monitoring And Management
    Vendor
    Zohocorp
    Product
    Manageengine Secure Gateway Server
    Vendor
    Zohocorp
    Product
    Manageengine Servicedesk Plus
    Vendor
    Zohocorp
    Product
    Manageengine Servicedesk Plus Msp
    Vendor
    Zohocorp
    Product
    Manageengine Sharepoint Manager Plus
    Vendor
    Zohocorp
    Product
    Manageengine Supportcenter Plus
    Vendor
    Zohocorp
    Product
    Manageengine Vulnerability Manager Plus

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High