CVE-2017-16924
9.8
CRITICAL · CVSS 3.0 · EPSS 8.6% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys. This is fixed in build 100157.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 8.6% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-330 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-02-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zohocorp | manageengine desktop central |
References
- https://github.com/snoonan77/security-research/blob/master/CVE-2017-16924
- https://www.manageengine.com/desktop-management-msp/password-encryption-policy-violation.html
- https://github.com/snoonan77/security-research/blob/master/CVE-2017-16924
- https://www.manageengine.com/desktop-management-msp/password-encryption-policy-violation.html
→ the Explorer · watch your stack · NVD