Integer Overflow Vulnerability in ManageEngine Asset Explorer Agent
CVE-2021-20110
What is CVE-2021-20110?
The vulnerability arises in ManageEngine Asset Explorer Agent 1.0.34 due to insufficient validation of HTTPS certificates, allowing attackers to impersonate the server by configuring their IP address to match that of the Asset Explorer server. This exploitation can enable an attacker to send malformed NEWSCAN requests and intercept authtoken verification HTTP requests. More critically, the flaw is linked to an Integer Overflow that occurs during the processing of a POST response, where an attacker can specify a dangerously large Content-Length, causing a wrap-around effect in memory allocation. This results in a Heap Overflow that could permit the execution of arbitrary code at the NT AUTHORITY/SYSTEM level, leading to severe security implications for systems running this software.
Affected Version(s)
Manage Engine Asset Explorer Agent 1.0.34