9.8

CVE-2021-41833

Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Patch Connect Plus Version9.0.0 Update-
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90001
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90063
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90064
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90065
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90066
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90067
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90068
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90069
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90070
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90071
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90072
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90073
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90074
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90075
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90076
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90077
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90078
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90079
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90080
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90081
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90082
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90083
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90084
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90085
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90086
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90087
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90088
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90089
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90090
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90091
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90092
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90093
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90094
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90095
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90096
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90097
ZohocorpManageengine Patch Connect Plus Version9.0.0 Updatebuild90098
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 27.31% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.