CVE-2020-10189
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
9.8
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2020-03-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| zohocorp | manageengine_desktop_central | < 10.0.479 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html
- https://cwe.mitre.org/data/definitions/502.html
- https://srcincite.io/advisories/src-2020-0011/
- https://srcincite.io/pocs/src-2020-0011.py.txt
- https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html
- https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/
- http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html
- https://cwe.mitre.org/data/definitions/502.html
- https://srcincite.io/advisories/src-2020-0011/
- https://srcincite.io/pocs/src-2020-0011.py.txt
- https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html
- https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-10189
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-10189