Cyber Posture

CVE-2025-1724

High

Published: 17 March 2025

Published
17 March 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.0097 76.8th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to CVE-2025-1724, an account takeover issue stemming from a hardcoded sensitive token, classified under CWE-798 (Use of Hard-coded Credentials). Published on 2025-03-17, this flaw carries a CVSS v3.1 base score of 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N), indicating high confidentiality and integrity impacts without affecting availability.

The vulnerability enables an attacker with network access to perform an Active Directory (AD)-only account takeover, requiring no privileges or user interaction but involving high attack complexity. Successful exploitation grants the attacker high-level access to the compromised AD account, potentially allowing unauthorized data access and modifications within the affected analytics platforms.

Official advisories from ManageEngine and Zoho detail mitigation steps, available at https://www.manageengine.com/analytics-plus/CVE-2025-1724.html and https://www.zoho.com/analytics/onpremise/CVE-2025-1724.html. Organizations should upgrade to version 6130 or later to address the hardcoded token issue.

Details

CWE(s)
CWE-798

MITRE ATT&CK Enterprise Techniques

T1078.002 Domain Accounts Stealth
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Hardcoded token enables remote AD account takeover (T1078.002 Domain Accounts) via network-accessible on-premise analytics application (T1190 Exploit Public-Facing Application).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References