VulnerabilityModified
CVE-2022-40770
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection.
HIGH 7.2EPSS 81.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 81.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 81.32% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- zohocorp/manageengine servicedesk plus · zohocorp/manageengine servicedesk plus msp · zohocorp/manageengine supportcenter plus
- Source
- cve@mitre.org
References
- https://manageengine.comVendor Advisory
- https://www.manageengine.com/products/service-desk/CVE-2022-40770.htmlVendor Advisory
- https://manageengine.comVendor Advisory
- https://www.manageengine.com/products/service-desk/CVE-2022-40770.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.