Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-94827
HistoryDec 02, 2021 - 12:00 a.m.

ZOHO ManageEngine Network Configuration Manager Command Injection Vulnerability

2021-12-0200:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
zoho
manageengine
network configuration manager
command injection
vulnerability
ping feature
user input
system commands

EPSS

0.054

Percentile

93.3%

ZOHO ManageEngine Network Configuration Manager is a multi-vendor network change, configuration and compliance management (Nccm) solution from ZOHO USA. A command injection vulnerability exists in ZOHO ManageEngine Network Configuration Manager, which stems from the product’s Ping feature that does not effectively filter user input data, and could be exploited by attackers to execute system commands.

EPSS

0.054

Percentile

93.3%