CVE-2024-5466

Zohocorp ManageEngine OpManager andRemote Monitoring and Management versions128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ManageEngineCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
zohocorpmanageengine_opmanager
𝑥
≤ 12.7
zohocorpmanageengine_opmanager
12.8:build128102
zohocorpmanageengine_opmanager
12.8:build128103
zohocorpmanageengine_opmanager
12.8:build128104
zohocorpmanageengine_opmanager
12.8:build128186
zohocorpmanageengine_opmanager
12.8:build128187
zohocorpmanageengine_opmanager_msp
𝑥
≤ 12.7
zohocorpmanageengine_opmanager_msp
12.8:build128102
zohocorpmanageengine_opmanager_msp
12.8:build128103
zohocorpmanageengine_opmanager_msp
12.8:build128104
zohocorpmanageengine_opmanager_msp
12.8:build128186
zohocorpmanageengine_opmanager_msp
12.8:build128187
zohocorpmanageengine_opmanager_plus
𝑥
≤ 12.7
zohocorpmanageengine_opmanager_plus
12.8:build128102
zohocorpmanageengine_opmanager_plus
12.8:build128103
zohocorpmanageengine_opmanager_plus
12.8:build128104
zohocorpmanageengine_opmanager_plus
12.8:build128186
zohocorpmanageengine_opmanager_plus
12.8:build128187
zohocorpmanageengine_remote_monitoring_and_management_central
-
𝑥
= Vulnerable software versions