CVE-2020-21642

CRITICALCVSS 9.8/10EPSS 7.73%

Last modified

CVE-2020-21642 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.. EPSS estimates a 7.73% chance of exploitation in the next 30 days.

Description

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
7.73%

93.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
ZohocorpManageengine Analytics Plus2.9Build2900
ZohocorpManageengine Analytics Plus3.0Build3000
ZohocorpManageengine Analytics Plus3.1Build3100
ZohocorpManageengine Analytics Plus3.2Build3200
ZohocorpManageengine Analytics Plus3.3Build3300
ZohocorpManageengine Analytics Plus3.4Build3400
ZohocorpManageengine Analytics Plus3.5Build3500
ZohocorpManageengine Analytics Plus3.6Build3600
ZohocorpManageengine Analytics Plus3.7Build3700
ZohocorpManageengine Analytics Plus3.8Build3800
ZohocorpManageengine Analytics Plus3.9Build3900
ZohocorpManageengine Analytics Plus4.0Build4000
ZohocorpManageengine Analytics Plus4.1Build4100
ZohocorpManageengine Analytics Plus4.2Build4200
ZohocorpManageengine Analytics Plus4.3Build4300

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-21642?
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
How severe is CVE-2020-21642?
CVE-2020-21642 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 7.73% probability of exploitation in the next 30 days.
How do I fix CVE-2020-21642?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-21642?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST