CVE-2022-35405
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-502
מוצרים מושפעים
zohocorp: manageengine access manager plus; zohocorp: manageengine pam360; zohocorp: manageengine password manager pro
קישורים
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-354… PatchVendor Advisory
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-354… PatchVendor Advisory
- http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource