CVE-2024-5466

EUVD-2024-46680
Zohocorp ManageEngine OpManager andĀ Remote Monitoring and Management versionsĀ 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ManageEngineCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_opmanager
𝑥
≤ 12.7
zohocorpmanageengine_opmanager
12.8:build128102
zohocorpmanageengine_opmanager
12.8:build128103
zohocorpmanageengine_opmanager
12.8:build128104
zohocorpmanageengine_opmanager
12.8:build128186
zohocorpmanageengine_opmanager
12.8:build128187
zohocorpmanageengine_opmanager_msp
𝑥
≤ 12.7
zohocorpmanageengine_opmanager_msp
12.8:build128102
zohocorpmanageengine_opmanager_msp
12.8:build128103
zohocorpmanageengine_opmanager_msp
12.8:build128104
zohocorpmanageengine_opmanager_msp
12.8:build128186
zohocorpmanageengine_opmanager_msp
12.8:build128187
zohocorpmanageengine_opmanager_plus
𝑥
≤ 12.7
zohocorpmanageengine_opmanager_plus
12.8:build128102
zohocorpmanageengine_opmanager_plus
12.8:build128103
zohocorpmanageengine_opmanager_plus
12.8:build128104
zohocorpmanageengine_opmanager_plus
12.8:build128186
zohocorpmanageengine_opmanager_plus
12.8:build128187
zohocorpmanageengine_remote_monitoring_and_management_central
-
𝑥
= Vulnerable software versions