Lucene search

K
cveMitreCVE-2021-44650
HistoryJan 12, 2022 - 2:15 p.m.

CVE-2021-44650

2022-01-1214:15:07
mitre
web.nvd.nist.gov
37
cve-2021-44650
zoho
manageengine
m365 manager plus
build 4419
remote command execution
proxy settings
security vulnerability

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

60.8%

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

Affected configurations

Nvd
Node
zohocorpmanageengine_m365_manager_plusRange<4.4
OR
zohocorpmanageengine_m365_manager_plusMatch4.4-
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4400
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4401
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4402
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4403
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4406
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4407
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4408
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4410
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4411
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4412
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4413
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4414
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4415
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4416
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4417
OR
zohocorpmanageengine_m365_manager_plusMatch4.4build4418
VendorProductVersionCPE
zohocorpmanageengine_m365_manager_plus*cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:*:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:-:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:build4400:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:build4401:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:build4402:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:build4403:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:build4406:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:build4407:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:build4408:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plus4.4cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:4.4:build4410:*:*:*:*:*:*
Rows per page:
1-10 of 181

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

High

EPSS

0.002

Percentile

60.8%

Related for CVE-2021-44650