Skip to content
COOEY

EXPOSURES › CVE-2022-35405

CVE-2022-35405

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-35405 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus allow remote code execution due to unpatched vulnerabilities.

Zoho ManageEngine's PAM360, Password Manager Pro, and Access Manager Plus have unpatched vulnerabilities that enable remote code execution, posing a significant security risk to users.

Shame score — Pattern of unpatched vulnerabilities and poor security posture by Zoho ManageEngine.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.