7.2

CVE-2023-29084

Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Admanager Plus Version7.1 Update7100
ZohocorpManageengine Admanager Plus Version7.1 Update7101
ZohocorpManageengine Admanager Plus Version7.1 Update7102
ZohocorpManageengine Admanager Plus Version7.1 Update7110
ZohocorpManageengine Admanager Plus Version7.1 Update7111
ZohocorpManageengine Admanager Plus Version7.1 Update7112
ZohocorpManageengine Admanager Plus Version7.1 Update7113
ZohocorpManageengine Admanager Plus Version7.1 Update7114
ZohocorpManageengine Admanager Plus Version7.1 Update7115
ZohocorpManageengine Admanager Plus Version7.1 Update7116
ZohocorpManageengine Admanager Plus Version7.1 Update7117
ZohocorpManageengine Admanager Plus Version7.1 Update7118
ZohocorpManageengine Admanager Plus Version7.1 Update7120
ZohocorpManageengine Admanager Plus Version7.1 Update7121
ZohocorpManageengine Admanager Plus Version7.1 Update7122
ZohocorpManageengine Admanager Plus Version7.1 Update7123
ZohocorpManageengine Admanager Plus Version7.1 Update7124
ZohocorpManageengine Admanager Plus Version7.1 Update7125
ZohocorpManageengine Admanager Plus Version7.1 Update7126
ZohocorpManageengine Admanager Plus Version7.1 Update7130
ZohocorpManageengine Admanager Plus Version7.1 Update7131
ZohocorpManageengine Admanager Plus Version7.1 Update7140
ZohocorpManageengine Admanager Plus Version7.1 Update7141
ZohocorpManageengine Admanager Plus Version7.1 Update7150
ZohocorpManageengine Admanager Plus Version7.1 Update7151
ZohocorpManageengine Admanager Plus Version7.1 Update7160
ZohocorpManageengine Admanager Plus Version7.1 Update7161
ZohocorpManageengine Admanager Plus Version7.1 Update7162
ZohocorpManageengine Admanager Plus Version7.1 Update7163
ZohocorpManageengine Admanager Plus Version7.1 Update7170
ZohocorpManageengine Admanager Plus Version7.1 Update7171
ZohocorpManageengine Admanager Plus Version7.1 Update7180
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 93.83% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.