{"api_version":"1","generated_at":"2026-07-23T22:22:09+00:00","cve":"CVE-2020-10189","urls":{"html":"https://cve.report/CVE-2020-10189","api":"https://cve.report/api/cve/CVE-2020-10189.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-10189","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-10189"},"summary":{"title":"CVE-2020-10189","description":"Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-03-06 17:15:00","updated_at":"2022-10-07 13:42:00"},"problem_types":["CWE-502"],"metrics":[],"references":[{"url":"https://srcincite.io/advisories/src-2020-0011/","name":"https://srcincite.io/advisories/src-2020-0011/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Source Incite","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://srcincite.io/pocs/src-2020-0011.py.txt","name":"https://srcincite.io/pocs/src-2020-0011.py.txt","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"","mime":"text/x-python","httpstatus":"200","archivestatus":"200"},{"url":"https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html","name":"https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html","refsource":"CONFIRM","tags":[],"title":"Remote Code Execution Vulnerability | ManageEngine Desktop Central","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html","name":"http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html","refsource":"MISC","tags":[],"title":"ManageEngine Desktop Central Java Deserialization ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/","name":"https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Zoho zero-day published on Twitter | ZDNet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cwe.mitre.org/data/definitions/502.html","name":"https://cwe.mitre.org/data/definitions/502.html","refsource":"MISC","tags":[],"title":"CWE -\r\n\n\t\tCWE-502: Deserialization of Untrusted Data (4.3)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-10189","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10189","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"10189","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zohocorp","cpe5":"manageengine_desktop_central","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"10189","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zohocorp","cpe5":"manageengine_desktop_central","cpe6":"10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"10189","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zohocorp","cpe5":"manageengine_desktop_central","cpe6":"10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2020","cve_id":"10189","cve":"CVE-2020-10189","vendorProject":"Zoho","product":"ManageEngine","vulnerabilityName":"Zoho ManageEngine Desktop Central File Upload Vulnerability","dateAdded":"2021-11-03","shortDescription":"Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2020-10189","cwes":"CWE-502","catalogVersion":"2026.07.23","updated_at":"2026-07-23 17:19:19"},"epss":{"cve_year":"2020","cve_id":"10189","cve":"CVE-2020-10189","epss":"0.999410000","percentile":"0.999710000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:34"},"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-10189","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://srcincite.io/advisories/src-2020-0011/","refsource":"MISC","name":"https://srcincite.io/advisories/src-2020-0011/"},{"url":"https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/","refsource":"MISC","name":"https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/"},{"url":"https://srcincite.io/pocs/src-2020-0011.py.txt","refsource":"MISC","name":"https://srcincite.io/pocs/src-2020-0011.py.txt"},{"refsource":"CONFIRM","name":"https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html","url":"https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html","url":"http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html"},{"refsource":"MISC","name":"https://cwe.mitre.org/data/definitions/502.html","url":"https://cwe.mitre.org/data/definitions/502.html"}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N","version":"3.0"}}},"nvd":{"publishedDate":"2020-03-06 17:15:00","lastModifiedDate":"2022-10-07 13:42:00","problem_types":["CWE-502"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.479","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"10189","Ordinal":"170598","Title":"CVE-2020-10189","CVE":"CVE-2020-10189","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"10189","Ordinal":"1","NoteData":"Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"10189","Ordinal":"2","NoteData":"2020-03-06","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"10189","Ordinal":"3","NoteData":"2020-03-14","Type":"Other","Title":"Modified"}]}}}