CVE-2021-28960

Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:manageengine:desktop_central:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:00

Type Values Removed Values Added
References () https://www.manageengine.com - Vendor Advisory () https://www.manageengine.com - Vendor Advisory
References () https://www.manageengine.com/products/desktop-central/unauthenticated-command-injection-vulnerability.html - Vendor Advisory () https://www.manageengine.com/products/desktop-central/unauthenticated-command-injection-vulnerability.html - Vendor Advisory

28 Nov 2021, 23:15

Type Values Removed Values Added
References (MISC) https://www.manageengine.com - Product (MISC) https://www.manageengine.com - Vendor Advisory

17 Nov 2021, 22:17

Type Values Removed Values Added
Summary ManageEngine Desktop Central before build 10.0.683 allows Unauthenticated Remote Code Execution during communication with Notification Server. Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

10 Nov 2021, 01:16

Type Values Removed Values Added
Summary Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations. ManageEngine Desktop Central before build 10.0.683 allows Unauthenticated Remote Code Execution during communication with Notification Server.

02 Nov 2021, 18:15

Type Values Removed Values Added
Summary ManageEngine Desktop Central before build 10.0.683 allows Unauthenticated Remote Code Execution during communication with Notification Server. Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

29 Sep 2021, 16:30

Type Values Removed Values Added
References (MISC) https://www.manageengine.com - (MISC) https://www.manageengine.com - Product
References (MISC) https://www.manageengine.com/products/desktop-central/unauthenticated-command-injection-vulnerability.html - (MISC) https://www.manageengine.com/products/desktop-central/unauthenticated-command-injection-vulnerability.html - Vendor Advisory
CPE cpe:2.3:a:manageengine:desktop_central:*:*:*:*:*:*:*:*
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8

21 Sep 2021, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-21 13:15

Updated : 2024-11-21 06:00


NVD link : CVE-2021-28960

Mitre link : CVE-2021-28960

CVE.ORG link : CVE-2021-28960


JSON object : View

Products Affected

manageengine

  • desktop_central
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')