CVE-2022-35405

Published Jul 19, 2022

Last updated a year ago

Overview

Description
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Exploit added on
Sep 22, 2022
Exploit action due
Oct 13, 2022
Required action
Apply updates per vendor instructions.

Weaknesses

nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending

Configurations