CVE-2020-10189
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Zoho ManageEngine Desktop Central File Upload Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-502
מוצרים מושפעים
zohocorp: manageengine desktop central
קישורים
- https://www.manageengine.com/products/desktop-central/remote-code-execution-vu… Vendor Advisory
- https://www.manageengine.com/products/desktop-central/remote-code-execution-vu… Vendor Advisory
- http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-… ExploitThird Party AdvisoryVDB Entry
- https://srcincite.io/advisories/src-2020-0011/ ExploitThird Party Advisory
- https://srcincite.io/pocs/src-2020-0011.py.txt ExploitThird Party Advisory
- http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-… ExploitThird Party AdvisoryVDB Entry
- https://srcincite.io/advisories/src-2020-0011/ ExploitThird Party Advisory
- https://srcincite.io/pocs/src-2020-0011.py.txt ExploitThird Party Advisory
- https://cwe.mitre.org/data/definitions/502.html Third Party Advisory
- https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/ Third Party Advisory