Authenticated Command Injection in Zoho ManageEngine Asset Explorer
CVE-2019-19034
7.2HIGH
What is CVE-2019-19034?
The Zoho ManageEngine Asset Explorer 6.5 vulnerability exposes a significant security risk by failing to properly validate the SCCM database username during the dynamic generation of scheduling commands. Attackers can exploit this oversight, leading to the execution of arbitrary commands on the Asset Explorer server with elevated privileges. This flaw poses a severe threat to the integrity and confidentiality of the affected systems, as it may allow unauthorized execution of malicious commands.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved