🔙 목록으로 돌아가기

CVE-2022-23779: Zoho ManageEngine - Internal Hostname Disclosure

TitleZoho ManageEngine - Internal Hostname Disclosure
Authorcckuailong
SeverityMedium
ImpactAn attacker could use the disclosed internal hostnames to plan targeted attacks, gain unauthorized access, or perform reconnaissance on the internal network.
RemediationApply the latest security patch or update provided by Zoho ManageEngine to fix the internal hostname disclosure vulnerability.
CVSS Score5.3
EPSS Score0.46707
CVE IDCVE-2022-23779
CWE IDCWE-200
Shodan Queryhttp.title:"manageengine desktop central 10"
Fofa Queryapp="ZOHO-ManageEngine-Desktop"title="manageengine desktop central 10"app="zoho-manageengine-desktop"
Tags cve cve2022 zoho exposure zohocorp vuln

🔍 Vulnerability Description

Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

🌐 HTTP Request

GET /themes HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23779.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-23779.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A