S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-11512 Scanner

CVE-2017-11512 scanner - Arbitrary File Downloads vulnerability in ManageEngine ServiceDesk

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-11512
7.5
CVSS

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
ManageEngine ServiceDeskby Zoho
9.3.9328
Updated Aug 22, 2026View on NVD →
Detail

ManageEngine ServiceDesk is a comprehensive help desk software that is designed to streamline the IT support operations of organizations. It offers businesses a centralized platform where they can manage tickets, perform asset management, and automate routine tasks. The software’s intuitive user interface and advanced features enable IT teams to provide better customer support and efficiently manage their IT infrastructure.

CVE-2017-11512 is a vulnerability that was discovered in the ManageEngine ServiceDesk 9.3.9328 version. The issue arises due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An attacker who gains access to the system can exploit the vulnerability to download any arbitrary file from the vulnerable system. Since the attacker can download any file, this may allow them to gain sensitive information or execute malicious code on the system.

When exploited, CVE-2017-11512 can lead to serious consequences for businesses. For hackers with malicious intent, the vulnerability can be a gateway to accessing sensitive information, tampering with data, executing unauthorized commands, or taking over control of the system. This weakness can be leveraged by advanced persistent threat (APT) groups to gain access to assets, infect systems with ransomware and steal confidential data.

At s4e.io, we focus on making vulnerability assessment and management easy. Our platform makes it possible for organizations, businesses, and individuals to assess their digital assets for vulnerabilities. With pro features, those who read this article can easily and quickly learn about vulnerabilities in their digital assets, identify security weaknesses, and manage them efficiently. With our help, you can be sure that your digital assets are secure and that potential vulnerabilities have been minimized or eliminated.

 

REFERENCES

Solution Advice

To protect against the CVE-2017-11512 vulnerability, the following precautions are recommended:

  • Patch the system by installing the relevant security updates issued by the vendor.
  • Implement firewalls and intrusion prevention systems (IPS) to detect and block network traffic containing exploit attempts.
  • Monitor system logs and network traffic to identify suspicious activity.
  • Restrict access to the system by applying access controls, role-based access, and multi-factor authentication.
  • Conduct vulnerability assessments and penetration tests to identify other potential security weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-11512 scanner - Arbitrary File Downloads vulnerability in ManageEngine ServiceDesk | S4E