CRITICAL

CVE-2022-35405

Zohocorp Manageengine Access Manager Plus 2022-07-19 CVSS v3.1
CVSS
9.8
KEV

Description

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

Summary dbcve.org

Unauthenticated remote code execution vulnerability affecting Zoho ManageEngine Password Manager Pro (versions prior to 12101) and PAM360 (versions prior to 5510). ManageEngine Access Manager Plus (prior to 4303) is also affected, though exploitation requires authentication. The critical CVSS 9.8 score reflects the unauthenticated, remote nature of exploitation on the two primary affected products.

Mitigation

Upgrade Password Manager Pro to 12101 or later, PAM360 to 5510 or later, and Access Manager Plus to 4303 or later. Until upgrades are applied, restrict network access to the management interfaces to trusted hosts only and monitor for anomalous activity.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

99.93%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE