CVE-2019-17421

Severity
7.8HIGH
EPSS
0.1%
top 75.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateMay 24

Description

Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xcv5-pjw7-mgp9: Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 122022-05-24
CVEList
CVE-2019-17421: Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 122019-11-21
CVE-2019-17421 (HIGH CVSS 7.8) | Incorrect file permissions on the p | cvebase.io