BDU:2023-00171CriticalConfirmedExploit available
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Share link
Anyone with the link can open this vulnerability.
Уязвимость программных продуктов ManageEngine связана с ошибками при обработке входных данных. Эксплуатация уязвимости может позволить нару…
CVSS
9.8
Critical
EPSS
0.00
p0
Published
2023-01-01
Updated
2023-01-01
Description
Уязвимость программных продуктов ManageEngine связана с ошибками при обработке входных данных. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, выполнить произвольный код путем отправки специально сформированного SAML-запроса
Tags · CWE
Pre-auth
Affected products
Zoho corp. Access manager plusZoho corp. Active directory 360Zoho corp. Admanager plusZoho corp. Analytics plusZoho corp. Application control plusZoho corp. Asset explorerZoho corp. Browser security plusZoho corp. Device control plusZoho corp. Endpoint centralZoho corp. Endpoint central mspZoho corp. Endpoint dlpZoho corp. Key manager plusZoho corp. Manageengine adselfservice plusZoho corp. Os deployerZoho corp. Pam360Zoho corp. Password manager proZoho corp. Patch manager plusZoho corp. Remote access plusZoho corp. Remote monitoring and management (rmm)Zoho corp. Servicedesk plus
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
BDU:2023-00171
bdu_exploit · https://bdu.fstec.ru/vul
CVE-2022-47966
github-poc · https://github.com/vonahisec/CVE-2022-47966-Scan
Affected software
| Product | Vendor | Status |
|---|---|---|
| access manager plus | zoho corp. | Tracked |
| active directory 360 | zoho corp. | Tracked |
| admanager plus | zoho corp. | Tracked |
| analytics plus | zoho corp. | Tracked |
| application control plus | zoho corp. | Tracked |
| asset explorer | zoho corp. | Tracked |
| browser security plus | zoho corp. | Tracked |
| device control plus | zoho corp. | Tracked |
| endpoint central | zoho corp. | Tracked |
| endpoint central msp | zoho corp. | Tracked |
| endpoint dlp | zoho corp. | Tracked |
| key manager plus | zoho corp. | Tracked |
| manageengine adselfservice plus | zoho corp. | Tracked |
| os deployer | zoho corp. | Tracked |
| pam360 | zoho corp. | Tracked |
| password manager pro | zoho corp. | Tracked |
| patch manager plus | zoho corp. | Tracked |
| remote access plus | zoho corp. | Tracked |
| remote monitoring and management (rmm) | zoho corp. | Tracked |
| servicedesk plus | zoho corp. | Tracked |
Source databases
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Related vulnerabilities