CVE-2020-10541: Critical severity manageengine opmanager msp vulnerability
Published Mar 13, 2020
·Updated
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
Affected Software
1 affected component
ZohoCorp ManageEngine OpManager<12.4.179
Event History
Mar 13, 2020
CVE Published
via MITRE·05:34 AM
Data Sourced
via MITRE·05:34 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Zoho ManageEngine OpManager?
The vulnerability ID for Zoho ManageEngine OpManager is CVE-2020-10541.
2
What is the severity of CVE-2020-10541?
The severity of CVE-2020-10541 is critical.
3
How does CVE-2020-10541 allow remote code execution?
CVE-2020-10541 allows remote code execution via a specially crafted Mail Server Settings v1 API request.
4
How can I check if my version of Zoho ManageEngine OpManager is affected by CVE-2020-10541?
If your version of Zoho ManageEngine OpManager is before 12.4.179, it is affected by CVE-2020-10541.
5
How can I fix CVE-2020-10541 in Zoho ManageEngine OpManager?
To fix CVE-2020-10541, you need to update Zoho ManageEngine OpManager to version 12.5.108 or later.