Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2021-3287

Severity
9.8CRITICAL
EPSS
88.5%
top 0.50%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 22
Latest updateMay 24

Description

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-9342-c88m-74xw: Zoho ManageEngine OpManager before 122022-05-24
CVEList
CVE-2021-3287: Zoho ManageEngine OpManager before 122021-04-22
VulnCheck
Zoho manageengine_opmanager Deserialization of Untrusted Data2021

💥Exploits & PoCs

1
Nuclei
Zoho ManageEngine OpManager < 12.5.329 - Remote Code Execution
CVE-2021-3287 (CRITICAL CVSS 9.8) | Zoho ManageEngine OpManager before | cvebase.io