9.8

CVE-2020-28653

Exploit

Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Opmanager Version < 12.5
ZohocorpManageengine Opmanager Version12.5 Updatebuild125000
ZohocorpManageengine Opmanager Version12.5 Updatebuild125002
ZohocorpManageengine Opmanager Version12.5 Updatebuild125100
ZohocorpManageengine Opmanager Version12.5 Updatebuild125101
ZohocorpManageengine Opmanager Version12.5 Updatebuild125102
ZohocorpManageengine Opmanager Version12.5 Updatebuild125108
ZohocorpManageengine Opmanager Version12.5 Updatebuild125110
ZohocorpManageengine Opmanager Version12.5 Updatebuild125111
ZohocorpManageengine Opmanager Version12.5 Updatebuild125112
ZohocorpManageengine Opmanager Version12.5 Updatebuild125113
ZohocorpManageengine Opmanager Version12.5 Updatebuild125114
ZohocorpManageengine Opmanager Version12.5 Updatebuild125116
ZohocorpManageengine Opmanager Version12.5 Updatebuild125117
ZohocorpManageengine Opmanager Version12.5 Updatebuild125118
ZohocorpManageengine Opmanager Version12.5 Updatebuild125120
ZohocorpManageengine Opmanager Version12.5 Updatebuild125121
ZohocorpManageengine Opmanager Version12.5 Updatebuild125123
ZohocorpManageengine Opmanager Version12.5 Updatebuild125124
ZohocorpManageengine Opmanager Version12.5 Updatebuild125125
ZohocorpManageengine Opmanager Version12.5 Updatebuild125136
ZohocorpManageengine Opmanager Version12.5 Updatebuild125137
ZohocorpManageengine Opmanager Version12.5 Updatebuild125139
ZohocorpManageengine Opmanager Version12.5 Updatebuild125140
ZohocorpManageengine Opmanager Version12.5 Updatebuild125143
ZohocorpManageengine Opmanager Version12.5 Updatebuild125144
ZohocorpManageengine Opmanager Version12.5 Updatebuild125145
ZohocorpManageengine Opmanager Version12.5 Updatebuild125156
ZohocorpManageengine Opmanager Version12.5 Updatebuild125157
ZohocorpManageengine Opmanager Version12.5 Updatebuild125158
ZohocorpManageengine Opmanager Version12.5 Updatebuild125159
ZohocorpManageengine Opmanager Version12.5 Updatebuild125161
ZohocorpManageengine Opmanager Version12.5 Updatebuild125163
ZohocorpManageengine Opmanager Version12.5 Updatebuild125174
ZohocorpManageengine Opmanager Version12.5 Updatebuild125175
ZohocorpManageengine Opmanager Version12.5 Updatebuild125176
ZohocorpManageengine Opmanager Version12.5 Updatebuild125177
ZohocorpManageengine Opmanager Version12.5 Updatebuild125178
ZohocorpManageengine Opmanager Version12.5 Updatebuild125180
ZohocorpManageengine Opmanager Version12.5 Updatebuild125181
ZohocorpManageengine Opmanager Version12.5 Updatebuild125192
ZohocorpManageengine Opmanager Version12.5 Updatebuild125193
ZohocorpManageengine Opmanager Version12.5 Updatebuild125194
ZohocorpManageengine Opmanager Version12.5 Updatebuild125195
ZohocorpManageengine Opmanager Version12.5 Updatebuild125196
ZohocorpManageengine Opmanager Version12.5 Updatebuild125197
ZohocorpManageengine Opmanager Version12.5 Updatebuild125198
ZohocorpManageengine Opmanager Version12.5 Updatebuild125201
ZohocorpManageengine Opmanager Version12.5 Updatebuild125204
ZohocorpManageengine Opmanager Version12.5 Updatebuild125212
ZohocorpManageengine Opmanager Version12.5 Updatebuild125213
ZohocorpManageengine Opmanager Version12.5 Updatebuild125214
ZohocorpManageengine Opmanager Version12.5 Updatebuild125215
ZohocorpManageengine Opmanager Version12.5 Updatebuild125216
ZohocorpManageengine Opmanager Version12.5 Updatebuild125228
ZohocorpManageengine Opmanager Version12.5 Updatebuild125229
ZohocorpManageengine Opmanager Version12.5 Updatebuild125230
ZohocorpManageengine Opmanager Version12.5 Updatebuild125231
ZohocorpManageengine Opmanager Version12.5 Updatebuild125232
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 79.17% 0.99
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P