CVE-2023-29505
CVE-2023-29505 is a medium-severity vulnerability in Zohocorp Manageengine Network Configuration Manager with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-346.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- EPSS exploit prediction: 1% (64th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-346
- Affected product: Zohocorp Manageengine Network Configuration Manager
- Published:
- Last modified:
Description
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
Frequently asked questions
- What is CVE-2023-29505?
- An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
- How severe is CVE-2023-29505?
- CVE-2023-29505 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2023-29505 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (64th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-29505?
- CVE-2023-29505 affects Zohocorp Manageengine Network Configuration Manager. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-29505?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-29505 published?
- CVE-2023-29505 was published on 2023-08-04 and last updated on 2026-06-17.
References
- https://cds.thalesgroup.com/en/tcs-cert/CVE-2023-29505
- https://excellium-services.com/cert-xlm-advisory/CVE-2023-29505
- https://www.manageengine.com/itom/advisory/cve-2023-29505.html
- https://www.manageengine.com/network-monitoring/help/read-me-complete.html#build_127131
Affected products (1)
- cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126165:*:*:*:*:*:*
More vulnerabilities in Zohocorp Manageengine Network Configuration Manager
- CVE-2021-43319 — Critical (CVSS 9.8): Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper…
- CVE-2021-41081 — Critical (CVSS 9.8): Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration…
- CVE-2021-41080 — Critical (CVSS 9.8): Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware…
- CVE-2023-47211 — Critical (CVSS 9.1): A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A…
- CVE-2022-38772 — High (CVSS 8.8): Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and…
- CVE-2022-37024 — High (CVSS 8.8): Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and…
All CVEs affecting Zohocorp Manageengine Network Configuration Manager →
Other CWE-346 vulnerabilities
- CVE-2026-42901 — Critical (CVSS 10.0): Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-84140 — Critical (CVSS 9.8): Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2,…
- CVE-2026-84133 — Critical (CVSS 9.8): Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR…
- CVE-2026-84129 — Critical (CVSS 9.8): Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2,…
- CVE-2026-16375 — Critical (CVSS 9.8): Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR…
- CVE-2026-16358 — Critical (CVSS 9.8): Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR…