Lucene search

K
cve[email protected]CVE-2022-48362
HistoryFeb 25, 2023 - 9:15 p.m.

CVE-2022-48362

2023-02-2521:15:10
CWE-22
web.nvd.nist.gov
52
cve-2022-48362
zoho manageengine
desktop central
directory traversal
agentloguploadservlet
security vulnerability

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.974 High

EPSS

Percentile

99.9%

Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)

Affected configurations

NVD
Node
zohocorpmanageengine_desktop_centralRange<10.1.2137.2-
OR
zohocorpmanageengine_desktop_centralRange<10.1.2137.2managed_service_providers

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.974 High

EPSS

Percentile

99.9%