List of security vulnerabilities fixed in Network Configuration Manager

This page contains a list of all security vulnerabilities fixed in Network Configuration Manager along with its CVE ID and fixed build number. Go to ManageEngine's Security Response Center to report vulnerabilities on ManageEngine products.

 

CVE ID

SynopsisSeverityFixed in versionLink to latest build
ZVE-2024-1132Previously, CSRF vulnerability (ZVE-2024-1132) was detected where the external users were able to utilize the network tools without authentication to perform ping or SNMP ping on network devices. This has now been fixed. (Reported by Jayateertha Guruprasad).Medium128103/128247Download
CVE-2022-37024Earlier, there was a Remote Code Execution (RCE) vulnerability in IPv6 address management reported by an anonymous working with Trend Micro Zero Day Initiative. This has been fixed now.High 126120 / 126105 / 126003 / 125658
CVE-2022-38772Earlier, there was a Remote Code Execution (RCE) vulnerability in IPv4 address management reported by an anonymous working with Trend Micro Zero Day Initiative. This has been fixed now.High 126120 / 126105 / 126003 / 125658
CVE-2022-36923A vulnerability resulted in unauthenticated access of the user API key. This issue has been fixed now. (Reported by Anonymous working with Trend Micro Zero Day Initiative)Critical 126118 / 126104 / 126002 / 125657

CVE-2022-35404

Unauthorized creation of files lead to high resource consumption. This has been fixed now.(Reported by Tenable)Medium125639/ 125655/ 126101

CVE-2022-24703

Earlier, there was a stored XSS vulnerability in the Schedule name field of Schedule page. This issue is fixed now.Medium125584

CVE-2021-43319

Earlier, there was a Remote Code Execution (RCE) vulnerability in the Ping functionality. This issue has been fixed now.High 125488/125457/125473

CVE-2021-41081

The SQL injection vulnerability issue in configuration search has now been fixed.High125465/125436/125455
CVE-2021-41080The SQL injection vulnerability issue in hardware details search has now been fixed.High125465/125436/125455
CVE-2021-20078Folder deletion due to Path Traversal vulnerability in Sparkgateway jarHigh125362, 125332 and 125347
CVE-2021-3287Unauthenticated Remote Code Execution (RCE) vulnerability due to general bypass for the deserialization class.Critical125220/125314
CVE-2020-12116Path Traversal VulnerabilityHigh124196/125125
CVE-2020-11946Unauthenticated access to API key disclosure from a servlet callHigh124188/125120
CVE-2020-11527File read vulnerability in Arbitrary fileHigh124181
CVE-2020-10541Remote Code Execution (RCE) vulnerability in Mail Server Settings v1 APIsHigh124172
CVE-2019-17421Incorrect file permissions on the packaged Nipper executable file.Medium124079 & 124099
InternalAn operator user could access some restricted folders by bypassing the session.High123241
CVE-2018-19403Unauthenticated Remote Code Execution (RCE) vulnerabilityHigh123231
CVE-2018-12997, CVE-2018-12998Arbitrary web script injection vulnerabilityHigh123169