Integer Overflow Vulnerability in ManageEngine Asset Explorer Agent
CVE-2021-20110

9.8CRITICAL

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
19 July 2021

What is CVE-2021-20110?

The vulnerability arises in ManageEngine Asset Explorer Agent 1.0.34 due to insufficient validation of HTTPS certificates, allowing attackers to impersonate the server by configuring their IP address to match that of the Asset Explorer server. This exploitation can enable an attacker to send malformed NEWSCAN requests and intercept authtoken verification HTTP requests. More critically, the flaw is linked to an Integer Overflow that occurs during the processing of a POST response, where an attacker can specify a dangerously large Content-Length, causing a wrap-around effect in memory allocation. This results in a Heap Overflow that could permit the execution of arbitrary code at the NT AUTHORITY/SYSTEM level, leading to severe security implications for systems running this software.

Affected Version(s)

Manage Engine Asset Explorer Agent 1.0.34

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.