7.2
CVE-2022-40770
- EPSS 65.9%
- Veröffentlicht 23.11.2022 03:15:10
- Zuletzt bearbeitet 28.04.2025 20:15:19
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Servicedesk Plus Version < 13.0
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13000
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13001
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13002
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13003
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13004
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13005
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13006
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13007
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13008
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13009
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13010
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version < 10.6
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update-
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10600
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10601
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10602
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10603
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10604
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10605
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10606
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10607
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10608
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10609
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10610
Zohocorp ≫ Manageengine Supportcenter Plus Version < 11.0
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11000
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11001
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11002
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11003
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11004
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11005
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11006
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11007
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11008
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11009
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11010
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11011
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11012
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11013
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11014
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11015
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11016
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11017
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11018
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11019
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11020
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11021
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11022
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11024
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11025
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 65.9% | 0.984 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.