CVE-2022-40770

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
zohocorpmanageengine_servicedesk_plus
𝑥
< 13.0
zohocorpmanageengine_servicedesk_plus
13.0:13000
zohocorpmanageengine_servicedesk_plus
13.0:13001
zohocorpmanageengine_servicedesk_plus
13.0:13002
zohocorpmanageengine_servicedesk_plus
13.0:13003
zohocorpmanageengine_servicedesk_plus
13.0:13004
zohocorpmanageengine_servicedesk_plus
13.0:13005
zohocorpmanageengine_servicedesk_plus
13.0:13006
zohocorpmanageengine_servicedesk_plus
13.0:13007
zohocorpmanageengine_servicedesk_plus
13.0:13008
zohocorpmanageengine_servicedesk_plus
13.0:13009
zohocorpmanageengine_servicedesk_plus
13.0:13010
zohocorpmanageengine_servicedesk_plus_msp
𝑥
< 10.6
zohocorpmanageengine_servicedesk_plus_msp
10.6
zohocorpmanageengine_servicedesk_plus_msp
10.6:10600
zohocorpmanageengine_servicedesk_plus_msp
10.6:10601
zohocorpmanageengine_servicedesk_plus_msp
10.6:10602
zohocorpmanageengine_servicedesk_plus_msp
10.6:10603
zohocorpmanageengine_servicedesk_plus_msp
10.6:10604
zohocorpmanageengine_servicedesk_plus_msp
10.6:10605
zohocorpmanageengine_servicedesk_plus_msp
10.6:10606
zohocorpmanageengine_servicedesk_plus_msp
10.6:10607
zohocorpmanageengine_servicedesk_plus_msp
10.6:10608
zohocorpmanageengine_servicedesk_plus_msp
10.6:10609
zohocorpmanageengine_servicedesk_plus_msp
10.6:10610
zohocorpmanageengine_supportcenter_plus
𝑥
< 11.0
zohocorpmanageengine_supportcenter_plus
11.0:11000
zohocorpmanageengine_supportcenter_plus
11.0:11001
zohocorpmanageengine_supportcenter_plus
11.0:11002
zohocorpmanageengine_supportcenter_plus
11.0:11003
zohocorpmanageengine_supportcenter_plus
11.0:11004
zohocorpmanageengine_supportcenter_plus
11.0:11005
zohocorpmanageengine_supportcenter_plus
11.0:11006
zohocorpmanageengine_supportcenter_plus
11.0:11007
zohocorpmanageengine_supportcenter_plus
11.0:11008
zohocorpmanageengine_supportcenter_plus
11.0:11009
zohocorpmanageengine_supportcenter_plus
11.0:11010
zohocorpmanageengine_supportcenter_plus
11.0:11011
zohocorpmanageengine_supportcenter_plus
11.0:11012
zohocorpmanageengine_supportcenter_plus
11.0:11013
zohocorpmanageengine_supportcenter_plus
11.0:11014
zohocorpmanageengine_supportcenter_plus
11.0:11015
zohocorpmanageengine_supportcenter_plus
11.0:11016
zohocorpmanageengine_supportcenter_plus
11.0:11017
zohocorpmanageengine_supportcenter_plus
11.0:11018
zohocorpmanageengine_supportcenter_plus
11.0:11019
zohocorpmanageengine_supportcenter_plus
11.0:11020
zohocorpmanageengine_supportcenter_plus
11.0:11021
zohocorpmanageengine_supportcenter_plus
11.0:11022
zohocorpmanageengine_supportcenter_plus
11.0:11024
zohocorpmanageengine_supportcenter_plus
11.0:11025
𝑥
= Vulnerable software versions