CVE-2022-38772
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 77.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 77.62% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- zohocorp/manageengine netflow analyzer · zohocorp/manageengine network configuration manager · zohocorp/manageengine opmanager · zohocorp/manageengine opmanager msp · zohocorp/manageengine opmanager plus · zohocorp/manageengine oputils
- Source
- cve@mitre.org
References
- https://manageengine.comVendor Advisory
- https://www.manageengine.com/itom/advisory/cve-2022-38772.htmlVendor Advisory
- https://manageengine.comVendor Advisory
- https://www.manageengine.com/itom/advisory/cve-2022-38772.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.