First published: Wed Nov 23 2022(Updated: )
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ServiceDesk Plus | <13.0 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13000 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13001 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13002 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13003 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13004 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13005 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13006 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13007 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13008 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13009 | |
Zoho ManageEngine ServiceDesk Plus | =13.0-13010 | |
Zoho ManageEngine ServiceDesk Plus MSP | <10.6 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10600 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10601 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10602 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10603 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10604 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10605 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10606 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10607 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10608 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10609 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10610 | |
ManageEngine SupportCenter Plus | <11.0 | |
ManageEngine SupportCenter Plus | =11.0-11000 | |
ManageEngine SupportCenter Plus | =11.0-11001 | |
ManageEngine SupportCenter Plus | =11.0-11002 | |
ManageEngine SupportCenter Plus | =11.0-11003 | |
ManageEngine SupportCenter Plus | =11.0-11004 | |
ManageEngine SupportCenter Plus | =11.0-11005 | |
ManageEngine SupportCenter Plus | =11.0-11006 | |
ManageEngine SupportCenter Plus | =11.0-11007 | |
ManageEngine SupportCenter Plus | =11.0-11008 | |
ManageEngine SupportCenter Plus | =11.0-11009 | |
ManageEngine SupportCenter Plus | =11.0-11010 | |
ManageEngine SupportCenter Plus | =11.0-11011 | |
ManageEngine SupportCenter Plus | =11.0-11012 | |
ManageEngine SupportCenter Plus | =11.0-11013 | |
ManageEngine SupportCenter Plus | =11.0-11014 | |
ManageEngine SupportCenter Plus | =11.0-11015 | |
ManageEngine SupportCenter Plus | =11.0-11016 | |
ManageEngine SupportCenter Plus | =11.0-11017 | |
ManageEngine SupportCenter Plus | =11.0-11018 | |
ManageEngine SupportCenter Plus | =11.0-11019 | |
ManageEngine SupportCenter Plus | =11.0-11020 | |
ManageEngine SupportCenter Plus | =11.0-11021 | |
ManageEngine SupportCenter Plus | =11.0-11022 | |
ManageEngine SupportCenter Plus | =11.0-11024 | |
ManageEngine SupportCenter Plus | =11.0-11025 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40770 has been rated as a high-severity vulnerability due to its potential for authenticated command injection by high-privileged users.
To fix CVE-2022-40770, you should upgrade to the latest version of Zoho ManageEngine ServiceDesk Plus, specifically version 13.0-13011 or later.
CVE-2022-40770 affects users of Zoho ManageEngine ServiceDesk Plus versions 13010 and prior, as well as certain versions of ServiceDesk Plus MSP.
CVE-2022-40770 impacts systems running vulnerable versions of Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus.
CVE-2022-40770 cannot be exploited remotely as it requires high-privilege authenticated access to execute the command injection.