VulnerabilityModified
CVE-2021-43319
Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.
CRITICAL 9.8EPSS 21.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 21.40% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- zohocorp/manageengine network configuration manager
- Source
- cve@mitre.org
References
- https://manageengine.comProduct
- https://www.manageengine.com/network-configuration-manager/release-notes.html#125488Release Notes, Vendor Advisory
- https://manageengine.comProduct
- https://www.manageengine.com/network-configuration-manager/release-notes.html#125488Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.