CVE-2022-35405
Description
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
Summary dbcve.org
Unauthenticated remote code execution vulnerability affecting Zoho ManageEngine Password Manager Pro (versions prior to 12101) and PAM360 (versions prior to 5510). ManageEngine Access Manager Plus (prior to 4303) is also affected, though exploitation requires authentication. The critical CVSS 9.8 score reflects the unauthenticated, remote nature of exploitation on the two primary affected products.
Mitigation
Upgrade Password Manager Pro to 12101 or later, PAM360 to 5510 or later, and Access Manager Plus to 4303 or later. Until upgrades are applied, restrict network access to the management interfaces to trusted hosts only and monitor for anomalous activity.