CVE-2021-28960

Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:manageengine:desktop_central:*:*:*:*:*:*:*:*

History

28 Nov 2021, 23:15

Type Values Removed Values Added
References (MISC) https://www.manageengine.com - Product (MISC) https://www.manageengine.com - Vendor Advisory

17 Nov 2021, 22:17

Type Values Removed Values Added
Summary ManageEngine Desktop Central before build 10.0.683 allows Unauthenticated Remote Code Execution during communication with Notification Server. Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

10 Nov 2021, 01:16

Type Values Removed Values Added
Summary Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations. ManageEngine Desktop Central before build 10.0.683 allows Unauthenticated Remote Code Execution during communication with Notification Server.

02 Nov 2021, 18:15

Type Values Removed Values Added
Summary ManageEngine Desktop Central before build 10.0.683 allows Unauthenticated Remote Code Execution during communication with Notification Server. Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

29 Sep 2021, 16:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CPE cpe:2.3:a:manageengine:desktop_central:*:*:*:*:*:*:*:*
CWE CWE-77
References (MISC) https://www.manageengine.com - (MISC) https://www.manageengine.com - Product
References (MISC) https://www.manageengine.com/products/desktop-central/unauthenticated-command-injection-vulnerability.html - (MISC) https://www.manageengine.com/products/desktop-central/unauthenticated-command-injection-vulnerability.html - Vendor Advisory

21 Sep 2021, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-21 13:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-28960

Mitre link : CVE-2021-28960

CVE.ORG link : CVE-2021-28960


JSON object : View

Products Affected

manageengine

  • desktop_central
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')