SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-35405

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 99.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 October 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.93% probability · 100th percentile
CISA KEV
Listed 22 September 2022 · due 13 October 2022
Weakness
CWE-502
Affected
zohocorp/manageengine access manager plus · zohocorp/manageengine pam360 · zohocorp/manageengine password manager pro
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html; https://nvd.nist.gov/vuln/detail/CVE-2022-35405

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.