CVE-2022-28219

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
zohocorpmanageengine_adaudit_plus
𝑥
≤ 6.0
zohocorpmanageengine_adaudit_plus
7.0:7000
zohocorpmanageengine_adaudit_plus
7.0:7002
zohocorpmanageengine_adaudit_plus
7.0:7003
zohocorpmanageengine_adaudit_plus
7.0:7004
zohocorpmanageengine_adaudit_plus
7.0:7005
zohocorpmanageengine_adaudit_plus
7.0:7006
zohocorpmanageengine_adaudit_plus
7.0:7007
zohocorpmanageengine_adaudit_plus
7.0:7008
zohocorpmanageengine_adaudit_plus
7.0:7050
zohocorpmanageengine_adaudit_plus
7.0:7051
zohocorpmanageengine_adaudit_plus
7.0:7052
zohocorpmanageengine_adaudit_plus
7.0:7053
zohocorpmanageengine_adaudit_plus
7.0:7054
𝑥
= Vulnerable software versions