CVE-2022-35405
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 October 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.93% probability · 100th percentile
- CISA KEV
- Listed 22 September 2022 · due 13 October 2022
- Weakness
- CWE-502
- Affected
- zohocorp/manageengine access manager plus · zohocorp/manageengine pam360 · zohocorp/manageengine password manager pro
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html; https://nvd.nist.gov/vuln/detail/CVE-2022-35405
References
- http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-Java-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.htmlPatch, Vendor Advisory
- http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-Java-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.htmlPatch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-35405US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.