CVE-2022-35405 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-10-13.
Description
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.93% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | yes — remediate by 2022-10-13 |
| Public exploit | none known |
| Published | 2022-07-19 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-09-22 |
| Due | 2022-10-13 |
| Vendor / product | Zoho / ManageEngine |
| Ransomware use | none reported |
Affected (3)
| Vendor | Product |
|---|---|
| zohocorp | manageengine access manager plus |
| zohocorp | manageengine pam360 |
| zohocorp | manageengine password manager pro |
References
- http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-Java-Deserialization.html
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html
- http://packetstormsecurity.com/files/167918/Zoho-Password-Manager-Pro-XML-RPC-Java-Deserialization.html
- https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-35405
→ the Explorer · watch your stack · NVD