Unauthenticated Command Injection in Zoho ManageEngine Desktop Central
CVE-2021-28960

9.8CRITICAL

Key Information:

Vendor
CVE Published:
21 September 2021

Summary

Zoho ManageEngine Desktop Central versions prior to build 10.0.683 are affected by an unauthenticated command injection vulnerability. This issue arises from the improper handling of user inputs during on-demand operations, allowing attackers to execute arbitrary commands without authentication. This vulnerability poses a risk by potentially allowing unauthorized access and manipulation of the system.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.