CVE-2022-35405
CVE Published | 2022-07-19 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | zohocorp |
Related Product(s) | manageengine_password_manager_pro, manageengine_access_manager_plus, manageengine_pam360 |
Exploitation Reported (CISA KEV) | 2022-09-22 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph