« Back to list

CVE-2025-3444

Status: AnalyzedMedium (6.5)—

Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-3444",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-3444",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-22T18:25:58.727731Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "affectedData": [
        {
          "vendor": "ManageEngine",
          "product": "ServiceDesk Plus MSP",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "14920",
              "versionType": "14910"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "ManageEngine",
          "product": "SupportCenter Plus",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "14920",
              "versionType": "14920"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-05-22T11:15:52.257",
  "references": [
    {
      "url": "https://www.manageengine.com/products/service-desk-msp/cve-2025-3444.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded."
    },
    {
      "lang": "es",
      "value": "Las versiones de Zohocorp ManageEngine ServiceDesk Plus MSP y SupportCenter Plus anteriores a 14920 son vulnerables a la inclusión de archivos locales (LFI) autenticados en el módulo de administración, donde se carga el contenido de la tarjeta de ayuda."
    }
  ],
  "lastModified": "2026-06-17T09:19:58.037",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0FFFD50-8AD8-4295-8A53-40146BE6D8AC",
              "versionEndIncluding": "14.8"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:14.9:14900:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B2B72D2-5FD7-4C7F-BE3F-CDA5064E025A"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:14.9:14910:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0591674-38E9-4A24-8998-F00D737ECDE7"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58ED6DA7-4212-4CD1-A428-067D2A30F7A1",
              "versionEndIncluding": "14.8"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:14.9:14900:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9AABAF1-F12C-4F56-92DD-D93B91663045"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:14.9:14910:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F3C4C6A-9014-4F33-9B8D-F9B2437FF631"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "0fc0942c-577d-436f-ae8e-945763c79b02"
}