9.8

CVE-2021-41833

Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update -
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90001
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90063
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90064
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90065
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90066
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90067
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90068
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90069
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90070
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90071
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90072
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90073
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90074
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90075
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90076
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90077
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90078
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90079
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90080
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90081
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90082
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90083
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90084
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90085
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90086
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90087
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90088
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90089
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90090
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90091
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90092
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90093
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90094
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90095
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90096
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90097
Zohocorp ≫ Manageengine Patch Connect Plus Version 9.0.0 Update build90098
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.76% 0.939
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://pitstop.manageengine.com/portal/en/community/topic/unauthenticated-remote-code-execution-vulnerability-solved
Patch
Vendor Advisory
https://www.manageengine.com/sccm-third-party-patch-management/kb/unauthenticated-remote-code-execution.html
Vendor Advisory