S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-23779 Scanner

Detects 'Information Disclosure' vulnerability in Zoho ManageEngine Desktop Central affects v. before 10.1.2137.8.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
6
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-23779
5.3
CVSS

Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Zoho ManageEngine Desktop Central is an all-in-one endpoint management software that allows IT administrators to automate and simplify their desktop and mobile device management tasks. The software is used by businesses of all sizes to help manage and secure their digital assets.

Recently, a new vulnerability has been detected within the Zoho ManageEngine Desktop Central software, identified as CVE-2022-23779. This vulnerability was found to be present in software versions before 10.1.2137.8, and can pose a serious security risk if left unaddressed.

When exploited, the CVE-2022-23779 vulnerability within Zoho ManageEngine Desktop Central can allow an attacker to obtain the internal hostname of the installed server. This information can then be used to increase the success rate of future attacks that exploit other vulnerabilities in the software. It can also lead to the unauthorized access of sensitive information and data, potentially resulting in serious damage to the reputation and financial stability of the affected organization.

With the s4e.io platform, individuals and organizations can easily and quickly learn about vulnerabilities in their digital assets. Through the platform's pro features, users can access detailed reports and analysis that highlight potential security risks in their environment. By staying ahead of emerging threats, users can take the necessary precautions to protect against vulnerabilities and secure their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken:

  • Update to the latest version of Zoho ManageEngine Desktop Central to ensure that the vulnerability has been addressed.
  • Review all settings and configurations to ensure that they are configured securely.
  • Use strong passwords and two-factor authentication to prevent unauthorized access.
  • Implement network security best practices, such as segmenting networks and restricting access to systems and data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-23779 scanner - Information Disclosure vulnerability in Zoho ManageEngine Desktop Central | S4E