CVE-2022-35405
KEV PoC largeDeserialization RCE in ManageEngine Password Manager Pro, PAM360, and Access Manager Plus
CISA: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain a flaw classified as deserialization of untrusted data (CWE-502) that allows an unauthenticated attacker to achieve remote code execution by sending crafted serialized data to the server. Because no authentication or user interaction is required, any client that can reach the product's network service can submit input that the application deserializes and executes. A successful attacker gains code execution with the privileges of the product's service, typically yielding control of the server and, critically, access to the vault of privileged credentials these products store, enabling lateral movement and ransomware campaigns. Any organization running one of these three ManageEngine password and access management products is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-22, and EPSS estimates a 99.9% probability of exploitation within 30 days.
What to do: Apply the updates Zoho released for all three products immediately, as CISA's required action specifies applying vendor updates: inventory whether you run Password Manager Pro, PAM360, or Access Manager Plus, and upgrade to the fixed builds named in each product's advisory. Until patched, restrict network access to the products' HTTPS management service (e.g., Password Manager Pro's default service port 7272) to trusted administrative networks only. After patching, hunt for signs of compromise such as unexpected processes, new accounts, or use of vaulted credentials, since the KEV listing implies exploitation and ransomware association is listed as unknown.
| Zoho ManageEngine Password Manager Pro | — |
| Zoho ManageEngine PAM360 | — |
| Zoho ManageEngine Access Manager Plus | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
- Affected
- Zoho ManageEngine
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zohocorp
- Products
- manageengine access manager plus, manageengine pam360, manageengine password manager pro
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H