CVE-2025-8309 Details
Description
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions before 14940, and SupportCenter Plus versions before 14940.
A privilege escalation vulnerability has been identified in multiple ManageEngine products, including Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus. This vulnerability arises from improper privilege management due to overly permissive regular expression rules in URL mapping, which can be exploited by low-privileged users to gain control of any account, including administrator accounts. The vulnerability affects Asset Explorer versions prior to 7710, ServiceDesk Plus versions prior to 15110, ServiceDesk Plus MSP versions prior to 14940, and SupportCenter Plus versions prior to 14940.
Users can upgrade to the latest version by downloading the service packs available on the ManageEngine website for Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus. After downloading, the latest build should be applied to the existing product installation according to the service pack instructions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/service-desk/cve-2025-8309.html | ManageEngine | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| ManageEngine AssetExplorer | <= 7700 |
CPE
Remediation
| |
| ManageEngine ServiceDesk Plus | <= 15100 |
CPE
Remediation
| |
| ManageEngine ServiceDesk Plus MSP | <= 14930 |
CPE
Remediation
| |
| ManageEngine SupportCenter Plus | <= 14930 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | New CVE Received | ManageEngine |
Volerion