{"api_version":"1","generated_at":"2026-07-23T19:19:20+00:00","cve":"CVE-2020-8838","urls":{"html":"https://cve.report/CVE-2020-8838","api":"https://cve.report/api/cve/CVE-2020-8838.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-8838","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-8838"},"summary":{"title":"CVE-2020-8838","description":"An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-03-23 17:15:00","updated_at":"2022-10-07 14:14:00"},"problem_types":["CWE-354"],"metrics":[],"references":[{"url":"https://www.manageengine.com/products/asset-explorer/sp-readme.html","name":"https://www.manageengine.com/products/asset-explorer/sp-readme.html","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"AssetExplorer ITAM Solution ServicePacks Readme","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://packetstormsecurity.com/files/157612/ManageEngine-Asset-Explorer-Windows-Agent-Remote-Code-Execution.html","name":"http://packetstormsecurity.com/files/157612/ManageEngine-Asset-Explorer-Windows-Agent-Remote-Code-Execution.html","refsource":"MISC","tags":[],"title":"ManageEngine Asset Explorer Windows Agent Remote Code Execution ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2020/May/29","name":"20200508 Asset Explorer Windows Agent - Remote Code Execution","refsource":"FULLDISC","tags":[],"title":"Full Disclosure: Asset Explorer Windows Agent - Remote Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-8838","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8838","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"8838","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zohocorp","cpe5":"manageengine_assetexplorer","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"8838","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zohocorp","cpe5":"manageengine_assetexplorer","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-8838","qid":"372459","title":"Zoho ManageEngine AssetExplorer Remote code execution vulnerability"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-8838","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://www.manageengine.com/products/asset-explorer/sp-readme.html","url":"https://www.manageengine.com/products/asset-explorer/sp-readme.html"},{"refsource":"FULLDISC","name":"20200508 Asset Explorer Windows Agent - Remote Code Execution","url":"http://seclists.org/fulldisclosure/2020/May/29"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/157612/ManageEngine-Asset-Explorer-Windows-Agent-Remote-Code-Execution.html","url":"http://packetstormsecurity.com/files/157612/ManageEngine-Asset-Explorer-Windows-Agent-Remote-Code-Execution.html"}]}},"nvd":{"publishedDate":"2020-03-23 17:15:00","lastModifiedDate":"2022-10-07 14:14:00","problem_types":["CWE-354"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.5,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:M/Au:S/C:P/I:P/A:P","accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.9},"severity":"MEDIUM","exploitabilityScore":4.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zohocorp:manageengine_assetexplorer:6.5:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"8838","Ordinal":"169188","Title":"CVE-2020-8838","CVE":"CVE-2020-8838","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"8838","Ordinal":"1","NoteData":"An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"8838","Ordinal":"2","NoteData":"2020-03-23","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"8838","Ordinal":"3","NoteData":"2020-05-08","Type":"Other","Title":"Modified"}]}}}