Security News > 2022 > September > Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)

Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)
2022-09-23 09:59

The US Cybersecurity and Infrastructure Security Agency has added CVE-2022-35405, a critical remote code execution vulnerability in ManageEngine PAM360, Password Manager Pro, and Access Manager Plus, to its Known Exploited Vulnerabilities Catalog.

CVE-2022-35405 is a remote code execution vulnerability that can be exploited to execute arbitrary code on affected installations of Password Manager Pro and PAM360 without prior authentication, and on Access Manager Plus with prior authentication.

"We have fixed this vulnerability by completely removing the vulnerable components from PAM360 and Access Manager Plus, and by removing the vulnerable parser from Password Manager Pro," ManageEngine stated in the advisory, and urged administrators to upgrade to a fixed version, as a proof-of-concept exploit was already public.

The vulnerability can be easily exploited and, depending on the targeted application, without requiring attackers to be authenticated and without the need for user interaction.

Under Binding Operational Directive 22-01, all US federal civilian executive branch agencies are required to remediate vulnerabilities in the KEV catalog within specific timeframes.

Vulnerabilities in ManageEngine applications are often taken advantage of by attackers.


News URL

https://www.helpnetsecurity.com/2022/09/23/cve-2022-35405-exploited/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-07-19 CVE-2022-35405 Deserialization of Untrusted Data vulnerability in Zohocorp products
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution.
network
low complexity
zohocorp CWE-502
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Manageengine 9 0 3 4 3 10