QID 372459

QID 372459: Zoho ManageEngine AssetExplorer Remote code execution vulnerability

Zoho ManageEngine AssetExplorer is an application performance monitoring solution that monitors business applications.

Affected Versions:
Zoho ManageEngine AssetExplorer 6.5

QID Detection Logic:(authenticated)
This QID sends request to the windows registry, and checks release version of buildinfo.xml of AssetExplorer in windows.

Successful exploitation of the vulnerability will lead to Remote Code Execution.

  • CVSS V3 rated as High - 6.4 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Vendor has released to fix this vulnerability.

    Download new version.

    CVEs related to QID 372459

    Software Advisories
    Advisory ID Software Component Link