7.2
CVE-2022-40770
- EPSS 76.61%
- Published 23.11.2022 03:15:10
- Last modified 28.04.2025 20:15:19
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
Data is provided by the National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Servicedesk Plus Version < 13.0
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13000
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13001
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13002
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13003
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13004
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13005
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13006
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13007
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13008
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13009
Zohocorp ≫ Manageengine Servicedesk Plus Version13.0 Update13010
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version < 10.6
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update-
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10600
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10601
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10602
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10603
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10604
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10605
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10606
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10607
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10608
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10609
Zohocorp ≫ Manageengine Servicedesk Plus Msp Version10.6 Update10610
Zohocorp ≫ Manageengine Supportcenter Plus Version < 11.0
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11000
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11001
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11002
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11003
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11004
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11005
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11006
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11007
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11008
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11009
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11010
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11011
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11012
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11013
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11014
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11015
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11016
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11017
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11018
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11019
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11020
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11021
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11022
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11024
Zohocorp ≫ Manageengine Supportcenter Plus Version11.0 Update11025
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 76.61% | 0.989 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.