Skip to content
COOEY

EXPOSURES › CVE-2020-10189

CVE-2020-10189

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-10189 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Unauthenticated remote code execution via file upload in Zoho ManageEngine Desktop Central.

An unauthenticated file upload vulnerability in Zoho ManageEngine Desktop Central allowed attackers to execute arbitrary code remotely. This is a critical failure for DIB organizations because it enables remote code execution (RCE) without authentication, directly violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure all ManageEngine products are patched immediately and assess their exposure to similar unpatched RCE flaws.

Shame score — The vulnerability allowed unauthenticated remote code execution, a severe flaw that was actively exploited in the wild (KEV) and reflects a pattern of unpatched critical RCE issues in the vendor's product line.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Unauthenticated RCE in a widely deployed enterprise management tool is a critical failure, though Zoho's response was relatively swift.
cooey ↗ severe-fallout -0.60
Critical vulnerability in a core management product, but no severe fallout or condemnation is evident in the provided text.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.