« Volver al listado

CVE-2025-11669

Estado: AnalizadaAlta (8.1)—

Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:L indica acceso remoto con privilegios necesarios (T1210). CWE-862 (falta de autorización) en funcionalidad de sesión remota permite escalada a cuentas o acceso no autorizado (T1078) y potencial lectura de datos sensibles (T1005) en sistemas PAM.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-11669",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-11669",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-14T04:57:27.565835Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "affectedData": [
        {
          "vendor": "Zohocorp",
          "product": "ManageEngine PAM360",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "8202",
              "versionType": "8202"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Zohocorp",
          "product": "ManageEngine Password Manager Pro",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "13221",
              "versionType": "13221"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Zohocorp",
          "product": "ManageEngine Access Manager Plus",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4401",
              "versionType": "4401"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-13T14:16:37.160",
  "references": [
    {
      "url": "https://www.manageengine.com/privileged-access-management/advisory/cve-2025-11669.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality."
    },
    {
      "lang": "es",
      "value": "Las versiones de Zohocorp ManageEngine PAM360 anteriores a la 8202; las versiones de Password Manager Pro anteriores a la 13221; y las versiones de Access Manager Plus anteriores a la 4401 son vulnerables a un problema de autorización en la funcionalidad de iniciar sesión remota."
    }
  ],
  "lastModified": "2026-06-17T08:30:57.850",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_pam360:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF414A47-847B-4423-85BA-3BE7721CB631",
              "versionEndExcluding": "8.2"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_pam360:8.2:build8200:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1942CE8-BDBD-4C8B-A1A5-BC343A403EF6"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_pam360:8.2:build8201:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C03FD6F2-1C37-4EDE-925C-2793DEA837D2"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "978659AB-47FC-4067-9D69-FAE21D87AE76",
              "versionEndExcluding": "4.4"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_access_manager_plus:4.4:build4400:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20880A1B-E33E-4028-935B-F6308397270D"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F6A6153-F358-4D49-9C30-50E418346769",
              "versionEndExcluding": "13.2"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:13.2:build13200:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7B3FD1F-E984-4BF5-BFDE-A4F8DF8D3252"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:13.2:build13210:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83144A70-3F05-427B-84BD-6D68575812B0"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:13.2:build13220:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FFFD4D0-0A63-4915-9BC6-016B3FA0BE98"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "0fc0942c-577d-436f-ae8e-945763c79b02"
}