CVE-2021-37929

EUVD-2021-24405
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_admanager_plus
𝑥
< 7.1
zohocorpmanageengine_admanager_plus
7.1
zohocorpmanageengine_admanager_plus
7.1:7100
zohocorpmanageengine_admanager_plus
7.1:7101
zohocorpmanageengine_admanager_plus
7.1:7102
zohocorpmanageengine_admanager_plus
7.1:7110
𝑥
= Vulnerable software versions