HTTP: ManageEngine Desktop Central Servlet AddPluginUser Action Admin Account Creation

This signature detects attempts to exploit a known vulnerability against ManageEngine Desktop. A successful exploit can lead to admin account creation.

Extended Description

The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.

Affected Products

Zohocorp desktop_central

References

CVE: CVE-2014-7862

Short Name
HTTP:MISC:MANAGE-ENGNE-ADMIN-AC
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Account Action AddPluginUser Admin CVE-2014-7862 Central Creation Desktop ManageEngine Servlet
Release Date
01/08/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Zohocorp

CVSS Score

7.5

Found a potential security threat?