CVE-2022-40770: Command Injection
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine ServiceDesk Plusto a version that resolves this vulnerability.Fixed in 13010
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40770?
CVE-2022-40770 has been rated as a high-severity vulnerability due to its potential for authenticated command injection by high-privileged users.
How do I fix CVE-2022-40770?
To fix CVE-2022-40770, you should upgrade to the latest version of Zoho ManageEngine ServiceDesk Plus, specifically version 13.0-13011 or later.
Who is affected by CVE-2022-40770?
CVE-2022-40770 affects users of Zoho ManageEngine ServiceDesk Plus versions 13010 and prior, as well as certain versions of ServiceDesk Plus MSP.
What types of systems are impacted by CVE-2022-40770?
CVE-2022-40770 impacts systems running vulnerable versions of Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus.
Can CVE-2022-40770 be exploited remotely?
CVE-2022-40770 cannot be exploited remotely as it requires high-privilege authenticated access to execute the command injection.