Home

Description

There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions before 14940, and SupportCenter Plus versions before 14940.

PUBLISHED Reserved 2025-07-29 | Published 2025-08-20 | Updated 2025-08-21 | Assigner Zohocorp




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

Any version before 7710
affected

Default status
unaffected

Any version before 15110
affected

Default status
unaffected

Any version before 14940
affected

Default status
unaffected

Any version before 14940
affected

References

www.manageengine.com/...ucts/service-desk/cve-2025-8309.html

cve.org (CVE-2025-8309)

nvd.nist.gov (CVE-2025-8309)

Download JSON