peter bassill · operator
$ cve CVE-2022-35405 JSON

CVE-2022-35405 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-10-13.

Description

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.93% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2022-10-13
Public exploitnone known
Published2022-07-19
Last modified2026-06-17

CISA KEV

NameZoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Added2022-09-22
Due2022-10-13
Vendor / productZoho / ManageEngine
Ransomware usenone reported

Affected (3)

VendorProduct
zohocorpmanageengine access manager plus
zohocorpmanageengine pam360
zohocorpmanageengine password manager pro

References

→ the Explorer  ·  watch your stack  ·  NVD