ManageEngine have released an important security update for Desktop Central and Mobile Device Manager Plus which addresses a file upload vulnerability. Read on for more details.
Issue: Arbitrary File Upload Vulnerability
What is the issue?
Desktop Central and Mobile Device Manager Plus allow users to upload Windows app dependency files in a ZIP format on to the product server.
Older builds had a vulnerability that allowed malicious users to upload a specially crafted ZIP file without proper validation, allowing them to potentially save files in any location
Who is affected?
Users running any of the below versions are at risk of exploitation:
Product | Affected Build Versions |
Desktop Central | Below build 100482 |
Desktop Central MSP | Below build 100482 |
Mobile Device Manager Plus | Between builds 92343 (released on May 16, 2018) and 92788 (released on March 22, 2020) |
Mobile Device Manager Plus MSP | between builds 92343 (released on May 16, 2018) and 92788 (released on March 22, 2020) |
How severe is this vulnerability?
The CVSS categorisation of the vulnerability is High.
To exploit this vulnerability, the user must authenticate themselves
by logging in to the product console. They also need permissions
to add apps to the App Repository. These two prerequisites reduce
the chance of someone exploiting this vulnerability.
What steps did the team take to mitigate this vulnerability?
The fix for this vulnerability was released in build number 100482
for Desktop Central and Desktop Central MSP, and build number 92789 for Mobile Device Manager Plus and Mobile Device Manager
Plus MSP.
The following steps were taken:
- All the uploaded ZIP files were validated, and any files with
path traversal capabilities were removed. - Only the required files were extracted instead of the entire
ZIP file. Before extraction, all file extensions and content
were verified, and only files required for the particular function
were extracted.
How can you fix this issue?
Desktop Central and Desktop Central MSP customers are requested
to upgrade to the latest build.
Important note: before upgrading please take all possible forms of backup.
Follow the steps below to upgrade:
1. Log in to the product console. In the top-right corner, click the
build number.
2. Upon clicking your current build version, you will be able to find
the latest build that’s applicable to your network.
3. Download the available PPM and upgrade to the latest build.
Mobile Device Manager Plus customers and Mobile Device
Manager Plus MSP customers are requested to upgrade to
the latest build available at the following links:
Mobile Device Manager Plus MSP
As a preventive measure, we also recommend you change the
default login credentials of your product server.
Desktop Central customers can change the default login credentials by clicking
on the user profile in the top-right corner and selecting Personalise. Then select Change password and provide a new password.
Mobile Device Manager Plus customers can change it by
navigating to Admin > Personalize > Change Password.
Please contact us here for more information, with any questions, or for any help updating your applications.
Other recent articles in the same category
You may be interested in these other recent articles
Last Week’s Best ManageEngine Updates – Part 30
6 December 2023 | Nazim Nadir
ManageEngine is named a strong performer for 2023 in last week updates. There are also new updates to their suite of applications and they have…
Read moreLast Week’s Best ManageEngine Updates – Part 29
27 November 2023 | Nazim Nadir
Exciting news of ManageEngine Linkedin Live webinar has been announced alongside some application updates and the release of a new E-Book. Whether you’re new to…
Read moreLast Week’s Best ManageEngine Updates – Part 28
30 October 2023 | Nazim Nadir
Updates on stability have been made by ManageEngine to enhance your end-user experience with their products. Continue reading to learn which ManageEngine applications gain the…
Read more