9.8
CVE-2021-41833
- EPSS 27.31%
- Veröffentlicht 11.11.2021 05:15:09
- Zuletzt bearbeitet 21.11.2024 06:26:50
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Patch Connect Plus Version < 9.0.0
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Update-
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90001
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90063
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90064
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90065
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90066
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90067
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90068
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90069
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90070
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90071
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90072
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90073
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90074
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90075
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90076
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90077
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90078
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90079
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90080
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90081
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90082
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90083
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90084
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90085
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90086
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90087
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90088
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90089
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90090
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90091
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90092
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90093
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90094
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90095
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90096
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90097
Zohocorp ≫ Manageengine Patch Connect Plus Version9.0.0 Updatebuild90098
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 27.31% | 0.959 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.