9.8
CVE-2021-41833
- EPSS 7.76%
- Veröffentlicht 11.11.2021 05:15:09
- Zuletzt bearbeitet 21.11.2024 06:26:50
- Erkennungen
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Patch Connect Plus Version < 9.0.0
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update -
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90001
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90063
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90064
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90065
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90066
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90067
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90068
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90069
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90070
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90071
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90072
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90073
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90074
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90075
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90076
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90077
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90078
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90079
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90080
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90081
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90082
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90083
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90084
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90085
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90086
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90087
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90088
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90089
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90090
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90091
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90092
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90093
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90094
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90095
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90096
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90097
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90098
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.76% | 0.939 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://pitstop.manageengine.com/portal/en/community/topic/unauthenticated-remote-code-execution-vulnerability-solved
https://www.manageengine.com/sccm-third-party-patch-management/kb/unauthenticated-remote-code-execution.html