EXPOSURES › CVE-2022-35405
CVE-2022-35405
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus allow remote code execution due to unpatched vulnerabilities.
Zoho ManageEngine's PAM360, Password Manager Pro, and Access Manager Plus have unpatched vulnerabilities that enable remote code execution, posing a significant security risk to users.
Shame score — Pattern of unpatched vulnerabilities and poor security posture by Zoho ManageEngine.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.