Lucene search

K
nvd[email protected]NVD:CVE-2023-38743
HistorySep 11, 2023 - 7:15 p.m.

CVE-2023-38743

2023-09-1119:15:42
web.nvd.nist.gov
5
zoho manageengine
admanager plus
vulnerability
command execution
build 7200

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.5%

Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.

Affected configurations

Nvd
Node
zohocorpmanageengine_admanager_plusRange<7.2
VendorProductVersionCPE
zohocorpmanageengine_admanager_plus*cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

55.5%

Related for NVD:CVE-2023-38743