5
CVSSv2

CVE-2014-5377

Published: 04/09/2014 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ReadUsersFromMasterServlet in ManageEngine DeviceExpert prior to 5.9 build 5981 allows remote malicious users to obtain user account credentials via a direct request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

manageengine device expert

Exploits

>> User credential disclosure in ManageEngine DeviceExpert 59 >> Discovered by Pedro Ribeiro (pedrib@gmailcom), Agile Information Security ========================================================================== >> Background on the affected product: "DeviceExpert is a web–based, multi vendor network change, configuration a ...
ManageEngine DeviceExpert version 59 suffers from a user credential disclosure vulnerability ...