CWE
77
Advisory Published
Updated

CVE-2021-43319: Command Injection

First published: Tue Nov 30 2021(Updated: )

Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Zohocorp Manageengine Network Configuration Manager=11.0
Zohocorp Manageengine Network Configuration Manager=11.0-build11000
Zohocorp Manageengine Network Configuration Manager=12.0
Zohocorp Manageengine Network Configuration Manager=12.0-build12000
Zohocorp Manageengine Network Configuration Manager=12.1
Zohocorp Manageengine Network Configuration Manager=12.1-build12100
Zohocorp Manageengine Network Configuration Manager=12.2
Zohocorp Manageengine Network Configuration Manager=12.2-build12200
Zohocorp Manageengine Network Configuration Manager=12.3
Zohocorp Manageengine Network Configuration Manager=12.3-build12300
Zohocorp Manageengine Network Configuration Manager=12.3-build123008
Zohocorp Manageengine Network Configuration Manager=12.3-build123023
Zohocorp Manageengine Network Configuration Manager=12.3-build123035
Zohocorp Manageengine Network Configuration Manager=12.3-build123052
Zohocorp Manageengine Network Configuration Manager=12.3-build123055
Zohocorp Manageengine Network Configuration Manager=12.3-build123057
Zohocorp Manageengine Network Configuration Manager=12.3-build123064
Zohocorp Manageengine Network Configuration Manager=12.3-build123069
Zohocorp Manageengine Network Configuration Manager=12.3-build123070
Zohocorp Manageengine Network Configuration Manager=12.3-build123083
Zohocorp Manageengine Network Configuration Manager=12.3-build123091
Zohocorp Manageengine Network Configuration Manager=12.3-build123105
Zohocorp Manageengine Network Configuration Manager=12.3-build123106
Zohocorp Manageengine Network Configuration Manager=12.3-build123123
Zohocorp Manageengine Network Configuration Manager=12.3-build123129
Zohocorp Manageengine Network Configuration Manager=12.3-build123137
Zohocorp Manageengine Network Configuration Manager=12.3-build123151
Zohocorp Manageengine Network Configuration Manager=12.3-build123156
Zohocorp Manageengine Network Configuration Manager=12.3-build123159
Zohocorp Manageengine Network Configuration Manager=12.3-build123169
Zohocorp Manageengine Network Configuration Manager=12.3-build123177
Zohocorp Manageengine Network Configuration Manager=12.3-build123179
Zohocorp Manageengine Network Configuration Manager=12.3-build123191
Zohocorp Manageengine Network Configuration Manager=12.3-build123194
Zohocorp Manageengine Network Configuration Manager=12.3-build123206
Zohocorp Manageengine Network Configuration Manager=12.3-build123207
Zohocorp Manageengine Network Configuration Manager=12.3-build123214
Zohocorp Manageengine Network Configuration Manager=12.3-build123215
Zohocorp Manageengine Network Configuration Manager=12.3-build123217
Zohocorp Manageengine Network Configuration Manager=12.3-build123218
Zohocorp Manageengine Network Configuration Manager=12.3-build123222
Zohocorp Manageengine Network Configuration Manager=12.3-build123223
Zohocorp Manageengine Network Configuration Manager=12.3-build123231
Zohocorp Manageengine Network Configuration Manager=12.3-build123237
Zohocorp Manageengine Network Configuration Manager=12.3-build123239
Zohocorp Manageengine Network Configuration Manager=12.3-build123274
Zohocorp Manageengine Network Configuration Manager=12.3-build123277
Zohocorp Manageengine Network Configuration Manager=12.3-build123279
Zohocorp Manageengine Network Configuration Manager=12.3-build123288
Zohocorp Manageengine Network Configuration Manager=12.3-build123304
Zohocorp Manageengine Network Configuration Manager=12.3-build123306
Zohocorp Manageengine Network Configuration Manager=12.3-build123312
Zohocorp Manageengine Network Configuration Manager=12.3-build123323
Zohocorp Manageengine Network Configuration Manager=12.3-build123327
Zohocorp Manageengine Network Configuration Manager=12.4
Zohocorp Manageengine Network Configuration Manager=12.4-build124000
Zohocorp Manageengine Network Configuration Manager=12.4-build124022
Zohocorp Manageengine Network Configuration Manager=12.4-build124024
Zohocorp Manageengine Network Configuration Manager=12.4-build124026
Zohocorp Manageengine Network Configuration Manager=12.4-build124031
Zohocorp Manageengine Network Configuration Manager=12.4-build124041
Zohocorp Manageengine Network Configuration Manager=12.4-build124043
Zohocorp Manageengine Network Configuration Manager=12.4-build124057
Zohocorp Manageengine Network Configuration Manager=12.4-build124073
Zohocorp Manageengine Network Configuration Manager=12.4-build124079
Zohocorp Manageengine Network Configuration Manager=12.4-build124094
Zohocorp Manageengine Network Configuration Manager=12.4-build124095
Zohocorp Manageengine Network Configuration Manager=12.4-build124098
Zohocorp Manageengine Network Configuration Manager=12.4-build124099
Zohocorp Manageengine Network Configuration Manager=12.4-build124103
Zohocorp Manageengine Network Configuration Manager=12.4-build124104
Zohocorp Manageengine Network Configuration Manager=12.4-build124168
Zohocorp Manageengine Network Configuration Manager=12.4-build124172
Zohocorp Manageengine Network Configuration Manager=12.4-build124176
Zohocorp Manageengine Network Configuration Manager=12.4-build124177
Zohocorp Manageengine Network Configuration Manager=12.4-build124181
Zohocorp Manageengine Network Configuration Manager=12.4-build124186
Zohocorp Manageengine Network Configuration Manager=12.4-build124188
Zohocorp Manageengine Network Configuration Manager=12.4-build124196
Zohocorp Manageengine Network Configuration Manager=12.5
Zohocorp Manageengine Network Configuration Manager=12.5-build125000
Zohocorp Manageengine Network Configuration Manager=12.5-build125108
Zohocorp Manageengine Network Configuration Manager=12.5-build125112
Zohocorp Manageengine Network Configuration Manager=12.5-build125115
Zohocorp Manageengine Network Configuration Manager=12.5-build125116
Zohocorp Manageengine Network Configuration Manager=12.5-build125120
Zohocorp Manageengine Network Configuration Manager=12.5-build125121
Zohocorp Manageengine Network Configuration Manager=12.5-build125125
Zohocorp Manageengine Network Configuration Manager=12.5-build125129
Zohocorp Manageengine Network Configuration Manager=12.5-build125136
Zohocorp Manageengine Network Configuration Manager=12.5-build125142
Zohocorp Manageengine Network Configuration Manager=12.5-build125149
Zohocorp Manageengine Network Configuration Manager=12.5-build125180
Zohocorp Manageengine Network Configuration Manager=12.5-build125195
Zohocorp Manageengine Network Configuration Manager=12.5-build125199
Zohocorp Manageengine Network Configuration Manager=12.5-build125212
Zohocorp Manageengine Network Configuration Manager=12.5-build125213
Zohocorp Manageengine Network Configuration Manager=12.5-build125216
Zohocorp Manageengine Network Configuration Manager=12.5-build125228
Zohocorp Manageengine Network Configuration Manager=12.5-build125232
Zohocorp Manageengine Network Configuration Manager=12.5-build125233
Zohocorp Manageengine Network Configuration Manager=12.5-build125234
Zohocorp Manageengine Network Configuration Manager=12.5-build125323
Zohocorp Manageengine Network Configuration Manager=12.5-build125325
Zohocorp Manageengine Network Configuration Manager=12.5-build125327
Zohocorp Manageengine Network Configuration Manager=12.5-build125329
Zohocorp Manageengine Network Configuration Manager=12.5-build125343
Zohocorp Manageengine Network Configuration Manager=12.5-build125345
Zohocorp Manageengine Network Configuration Manager=12.5-build125358
Zohocorp Manageengine Network Configuration Manager=12.5-build125362
Zohocorp Manageengine Network Configuration Manager=12.5-build125363
Zohocorp Manageengine Network Configuration Manager=12.5-build125378
Zohocorp Manageengine Network Configuration Manager=12.5-build125392
Zohocorp Manageengine Network Configuration Manager=12.5-build125399
Zohocorp Manageengine Network Configuration Manager=12.5-build125417
Zohocorp Manageengine Network Configuration Manager=12.5-build125436
Zohocorp Manageengine Network Configuration Manager=12.5-build125445
Zohocorp Manageengine Network Configuration Manager=12.5-build125455
Zohocorp Manageengine Network Configuration Manager=12.5-build125465
Zohocorp Manageengine Network Configuration Manager=12.5-build125469
Zohocorp Manageengine Network Configuration Manager=12.5-build125471
Zohocorp Manageengine Network Configuration Manager=12.5-build125482
Zohocorp Manageengine Network Configuration Manager=12.5-build125483
Zohocorp Manageengine Network Configuration Manager=12.5-build125485

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2021-43319 vulnerability about?

    CVE-2021-43319 is a command injection vulnerability in Zoho ManageEngine Network Configuration Manager before version 125488 due to improper validation in the Ping functionality.

  • How severe is CVE-2021-43319 vulnerability?

    CVE-2021-43319 vulnerability has a severity level of 9.8 (Critical).

  • What versions of Zoho ManageEngine Network Configuration Manager are affected by CVE-2021-43319?

    Versions 11.0 up to 12.5-build125485 of Zoho ManageEngine Network Configuration Manager are affected by CVE-2021-43319.

  • Are there any references related to CVE-2021-43319 vulnerability?

    Yes, references related to CVE-2021-43319 vulnerability can be found at manageengine.com and the release notes for Network Configuration Manager version 125488.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203