CVE-2024-5466

HIGH

ManageEngine OpManager and OpManager MSP < 12.7 - Authenticated Remote Code Execution via Deploy Agent Option

Title source: llm
STIX 2.1

Description

Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.1997
EPSS Percentile 95.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (7)
zohocorp/manageengine_opmanager 12.8 build128102 (5 CPE variants)
zohocorp/manageengine_opmanager < 12.7
zohocorp/manageengine_opmanager_msp 12.8 build128102 (5 CPE variants)
zohocorp/manageengine_opmanager_msp < 12.7
zohocorp/manageengine_opmanager_plus 12.8 build128102 (5 CPE variants)
zohocorp/manageengine_opmanager_plus < 12.7
zohocorp/manageengine_remote_monitoring_and_management_central
Published Aug 23, 2024
Tracked Since Feb 18, 2026