CVE-2020-15595

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Sep 30, 2020
Updated: Dec 18, 2024

Summary

CVE-2020-15595 is a vulnerability affecting Zoho Application Control Plus before version 10.0.511. This issue allows an attacker to retrieve the complete list of IP ranges and subnets configured within the product, providing insight into the internal network architecture that the product has access to, through the Element Configuration feature. The potential impact of this vulnerability includes unauthorized exposure of network information for potential further exploitation. Users are advised to upgrade to the latest version of Zoho Application Control Plus to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share