CISA Warns of Hackers Exploiting Recent Zoho ManageEngine Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-35405 | Deserialization RCE in ManageEngine Password Manager Pro, PAM360, and Access Manager Plus Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain a flaw classified as deserialization of untrusted data (CWE-502) that allows an unauthenticated attacker to achieve remote code execution by sending crafted serialized data to the server. Because no authentication or user interaction is required, any client that can reach the product's network service can submit input that the application deserializes and executes. A successful attacker gains code execution with the privileges of the product's service, typically yielding control of the server and, critically, access to the vault of privileged credentials these products store, enabling lateral movement and ransomware campaigns. Any organization running one of these three ManageEngine password and access management products is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-22, and EPSS estimates a 99.9% probability of exploitation within 30 days. Do: Apply the updates Zoho released for all three products immediately, as CISA's required action specifies applying vendor updates: inventory whether you run Password Manager Pro, PAM360, or Access Manager Plus, and upgrade to the fixed builds named in each product's advisory. Until patched, restrict network access to the products' HTTPS management service (e.g., Password Manager Pro's default service port 7272) to trusted administrative networks only. After patching, hunt for signs of compromise such as unexpected processes, new accounts, or use of vaulted credentials, since the KEV listing implies exploitation and ransomware association is listed as unknown. | 9.8 | 100% | KEV PoC |
| largetens of thousands of enterprise deployments across the three products, including several thousand internet-exposed instances visible in public scans,… |
Full article257 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 23, 2022
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a recently disclosed security flaw in Zoho ManageEngine to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation.
"Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability which allows for remote code execution," the agency said in a notice.
The critical vulnerability, tracked as CVE-2022-35405, is rated 9.8 out of 10 for severity on the CVSS scoring system, and was patched by Zoho as part of updates released on June 24, 2022.
Although the exact nature of the flaw remains unknown, the India-based enterprise solutions company said it addressed the issue by removing the vulnerable components that could lead to the remote execution of arbitrary code.
Zoho has also warned of the public availability of a proof-of-concept (PoC) exploit for the vulnerability, making it imperative that customers move quickly to upgrade the instances of Password Manager Pro, PAM360 and Access Manager Plus as soon as possible.
The cybersecurity agency did not share additional specifics on how the flaw is being weaponized and how widespread the exploitation efforts are, but data gathered by GreyNoise shows that in-the-wild attacks were detected on September 7, 2022.
In light of active exploitation of the vulnerability, Federal Civilian Executive Branch (FCEB) agencies are required to apply the vendor-provided patches by October 13, 2022.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/09/cisa-warns-of-hackers-exploiting-recent.html