First published: Fri Aug 23 2024(Updated: )
Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpManager MSP | <=12.7 | |
ManageEngine OpManager MSP | =12.8-build128102 | |
ManageEngine OpManager MSP | =12.8-build128103 | |
ManageEngine OpManager MSP | =12.8-build128104 | |
ManageEngine OpManager MSP | =12.8-build128186 | |
ManageEngine OpManager MSP | =12.8-build128187 | |
ManageEngine OpManager MSP | <=12.7 | |
ManageEngine OpManager MSP | =12.8-build128102 | |
ManageEngine OpManager MSP | =12.8-build128103 | |
ManageEngine OpManager MSP | =12.8-build128104 | |
ManageEngine OpManager MSP | =12.8-build128186 | |
ManageEngine OpManager MSP | =12.8-build128187 | |
ManageEngine OpManager Plus | <=12.7 | |
ManageEngine OpManager Plus | =12.8-build128102 | |
ManageEngine OpManager Plus | =12.8-build128103 | |
ManageEngine OpManager Plus | =12.8-build128104 | |
ManageEngine OpManager Plus | =12.8-build128186 | |
ManageEngine OpManager Plus | =12.8-build128187 | |
ManageEngine Remote Monitoring and Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5466 is categorized as a critical vulnerability due to the potential for authenticated remote code execution.
To mitigate CVE-2024-5466, update ManageEngine OpManager and Remote Monitoring and Management to version 12.8-build128188 or later.
CVE-2024-5466 affects ManageEngine OpManager and Remote Monitoring and Management versions 12.7 and below, and specific builds of version 12.8.
Yes, the exploitation of CVE-2024-5466 requires user authentication to carry out remote code execution.
CVE-2024-5466 can enable attackers to perform remote code execution which may lead to unauthorized access and control over affected systems.