🔙 목록으로 돌아가기

CVE-2022-35405: Zoho ManageEngine - Remote Code Execution

TitleZoho ManageEngine - Remote Code Execution
Authorviniciuspereiras,true13
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patch or update provided by Zoho ManageEngine to fix the vulnerability.
CVSS Score9.8
EPSS Score0.94314
CVE IDCVE-2022-35405
CWE IDCWE-502
Shodan Queryhttp.title:"ManageEngine"http.title:"manageengine"
Fofa Querytitle="manageengine"
Tags cve cve2022 rce zoho passwordmanager deserialization unauth msf kev zohocorp vkev vuln

🔍 Vulnerability Description

Zoho ManageEngine Password Manager Pro, PAM 360, and Access Manager Plus are susceptible to unauthenticated remote code execution via XML-RPC. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

POST /xmlrpc HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Safari/605.1.15
Connection: close
Content-Length: 153
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

<?xml version="1.0"?><methodCall><methodName>38EQhezNruW8IKheYel9wmd9o57</methodName><params><param><value>big0us</value></param></params></methodCall>

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-35405.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-35405.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A