Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-40770


Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.


Published

2022-11-23T03:15:10.280

Last Modified

2025-04-28T20:15:19.860

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zohocorp manageengine_servicedesk_plus < 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus 13.0 Yes
Application zohocorp manageengine_servicedesk_plus_msp < 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_supportcenter_plus < 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes
Application zohocorp manageengine_supportcenter_plus 11.0 Yes

References