QID 378356
Date Published: 2023-04-27
QID 378356: Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus Remote Code Execution (RCE) Vulnerability
Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus are vulnerable to RCE vulnerability when integrating with Analytics Plus.
The input fields needed to configure the Analytics Plus integration with ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus are vulnerable to remote command execution (RCE). Threat actors with admin role access can add malicious commands or scripts to these input fields during the setup of the integration and execute them.
Affected Versions:
ServiceDesk Plus 13010 and below
ServiceDesk Plus MSP 10610 and below
SupportCenter Plus 11025 and below
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus by reading the version from buildinfo.xml file.
Successful exploitation of this vulnerability may allows a threat actor with admin role access to execute arbitrary commands and carry out any subsequent attacks.
- Zoho ManageEngine Security Advisory -
www.manageengine.com/products/service-desk/CVE-2022-40770.html
CVEs related to QID 378356
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine Security Advisory |
|