CVE-2019-19034OS Command Injection in Manageengine Assetexplorer

Severity
7.2HIGHNVD
EPSS
20.9%
top 4.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMay 24

Description

Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-677g-x5rm-h62c: Zoho ManageEngine Asset Explorer 62022-05-24
CVEList
CVE-2019-19034: Zoho ManageEngine Asset Explorer 62020-03-23
CVE-2019-19034 — OS Command Injection | cvebase