Vulnerability record · CVE-2014-5377 · published 4 September 2014
CVE-2014-5377: ManageEngine DeviceExpert credential disclosure via ReadUsersFromMasterServlet
Manageengine · Device Expert
ManageEngine DeviceExpert before 5.9 build 5981 exposes user account credentials through the ReadUsersFromMasterServlet, which can be reached with a direct request. Because the servlet returns credentials without any apparent access control, an unauthenticated remote attacker can harvest account secrets from an internet-facing or network-reachable deployment.
Description
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote credential disclosure with public exploit code and very high EPSS probability, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
ManageEngine DeviceExpert before 5.9 build 5981 exposes user account credentials through the ReadUsersFromMasterServlet, which can be reached with a direct request. Because the servlet returns credentials without any apparent access control, an unauthenticated remote attacker can harvest account secrets from an internet-facing or network-reachable deployment.
Impact
An attacker obtains user account credentials, enabling account takeover and follow-on access to the DeviceExpert application and any managed devices or systems those credentials unlock.
Attack surface
Reachable over the network via HTTP against the ReadUsersFromMasterServlet endpoint. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Public exploit code exists in Packet Storm, Exploit-DB and Full Disclosure references, and EPSS is 0.57475 (99th percentile), indicating elevated likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded.
What to do
- Upgrade ManageEngine DeviceExpert to version 5.9 build 5981 or later, per the vendor release notes.
- If immediate patching is not possible, restrict network access to the DeviceExpert web interface and the ReadUsersFromMasterServlet endpoint using firewall rules or a reverse proxy.
- Require authentication and authorization for all servlet endpoints, and audit the application for other unauthenticated information-disclosure paths.
- Rotate all credentials stored or managed by DeviceExpert after patching, since exposure may already have occurred.
- Monitor vendor advisories and apply subsequent security updates promptly.
Detection
- Search web server and proxy logs for direct requests to ReadUsersFromMasterServlet, especially from unexpected source IPs.
- Alert on unauthenticated access to administrative or credential-serving servlet paths.
- Review authentication logs for anomalous logins using DeviceExpert-managed accounts following suspicious servlet access.
- Use network monitoring to detect scanning or enumeration of DeviceExpert endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-5377 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-5377), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.