Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15594

Опубликовано: 30 сент. 2020
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zohocorp:manageengine_application_control_plus:*:*:*:*:*:*:*:*
Версия до 10.0.511 (исключая)

EPSS

Процентиль: 65%
0.005
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.

EPSS

Процентиль: 65%
0.005
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-918