| Title | Zoho ManageEngine OpManager < 12.5.329 - Remote Code Execution |
|---|---|
| Author | theamanrawat |
| Severity | Critical |
| Impact | Unauthenticated attackers can execute arbitrary code remotely, leading to full system compromise. |
| Remediation | Update to version 12.5.329 or later. |
| CVSS Score | 9.8 |
| EPSS Score | 0.8849 |
| CVE ID | CVE-2021-3287 |
| CWE ID | CWE-502 |
| Shodan Query | http.title:"opmanager plus"http.title:"opmanager" |
| Fofa Query | title="opmanager plus"title="opmanager" |
| Tags | cve cve2021 deserialization rce opmanager passive vkev |
Zoho ManageEngine OpManager before 12.5.329 contains a remote code execution caused by a general bypass in the deserialization class, letting unauthenticated attackers execute arbitrary code, exploit requires no authentication
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3287.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-3287.pcap
N/AN/A