CVE-2015-9107
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt.
therefore, it's possible to create a universal decryptor.
CRITICAL · CVSS 9.8
EPSS 0.01665
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0