CVE-2022-40770

CWE-77Command Injection3 documents3 sources
Severity
7.2HIGH
EPSS
65.9%
top 1.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23

Description

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-r3rg-whrj-v9p8: Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection2022-11-23
CVEList
CVE-2022-40770: Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection2022-11-23
CVE-2022-40770 (HIGH CVSS 7.2) | Zoho ManageEngine ServiceDesk Plus | cvebase.io