Attacker Value
Unknown
0
CVE-2021-42099
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-42099
(Last updated October 07, 2023) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
9.8 Critical
Impact Score:
5.9
Exploitability Score:
3.9
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
n/a
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- manageengine m365 manager plus -,
- manageengine m365 manager plus build 4000,
- manageengine m365 manager plus build 4001,
- manageengine m365 manager plus build 4002,
- manageengine m365 manager plus build 4003,
- manageengine m365 manager plus build 4004,
- manageengine m365 manager plus build 4005,
- manageengine m365 manager plus build 4007,
- manageengine m365 manager plus build 4008,
- manageengine m365 manager plus build 4009,
- manageengine m365 manager plus build 4010,
- manageengine m365 manager plus build 4011,
- manageengine m365 manager plus build 4012,
- manageengine m365 manager plus build 4013,
- manageengine m365 manager plus build 4014,
- manageengine m365 manager plus build 4100,
- manageengine m365 manager plus build 4101,
- manageengine m365 manager plus build 4102,
- manageengine m365 manager plus build 4103,
- manageengine m365 manager plus build 4104,
- manageengine m365 manager plus build 4105,
- manageengine m365 manager plus build 4106,
- manageengine m365 manager plus build 4108,
- manageengine m365 manager plus build 4109,
- manageengine m365 manager plus build 4110,
- manageengine m365 manager plus build 4111,
- manageengine m365 manager plus build 4112,
- manageengine m365 manager plus build 4113,
- manageengine m365 manager plus build 4115,
- manageengine m365 manager plus build 4116,
- manageengine m365 manager plus build 4117,
- manageengine m365 manager plus build 4118,
- manageengine m365 manager plus build 4119,
- manageengine m365 manager plus build 4200,
- manageengine m365 manager plus build 4201,
- manageengine m365 manager plus build 4202,
- manageengine m365 manager plus build 4203,
- manageengine m365 manager plus build 4204,
- manageengine m365 manager plus build 4205,
- manageengine m365 manager plus build 4206,
- manageengine m365 manager plus build 4207,
- manageengine m365 manager plus build 4208,
- manageengine m365 manager plus build 4209,
- manageengine m365 manager plus build 4210,
- manageengine m365 manager plus build 4211,
- manageengine m365 manager plus build 4212,
- manageengine m365 manager plus build 4213,
- manageengine m365 manager plus build 4214,
- manageengine m365 manager plus build 4215,
- manageengine m365 manager plus build 4216,
- manageengine m365 manager plus build 4217,
- manageengine m365 manager plus build 4218,
- manageengine m365 manager plus build 4219,
- manageengine m365 manager plus build 4220,
- manageengine m365 manager plus build 4221,
- manageengine m365 manager plus build 4222,
- manageengine m365 manager plus build 4300,
- manageengine m365 manager plus build 4301,
- manageengine m365 manager plus build 4302,
- manageengine m365 manager plus build 4303,
- manageengine m365 manager plus build 4304,
- manageengine m365 manager plus build 4305,
- manageengine m365 manager plus build 4306,
- manageengine m365 manager plus build 4308,
- manageengine m365 manager plus build 4309,
- manageengine m365 manager plus build 4310,
- manageengine m365 manager plus build 4311,
- manageengine m365 manager plus build 4312,
- manageengine m365 manager plus build 4316,
- manageengine m365 manager plus build 4317,
- manageengine m365 manager plus build 4318,
- manageengine m365 manager plus build 4319,
- manageengine m365 manager plus build 4320,
- manageengine m365 manager plus build 4321,
- manageengine m365 manager plus build 4322,
- manageengine m365 manager plus build 4324,
- manageengine m365 manager plus build 4325,
- manageengine m365 manager plus build 4327,
- manageengine m365 manager plus build 4328,
- manageengine m365 manager plus build 4329,
- manageengine m365 manager plus build 4330,
- manageengine m365 manager plus build 4331,
- manageengine m365 manager plus build 4332,
- manageengine m365 manager plus build 4333,
- manageengine m365 manager plus build 4334,
- manageengine m365 manager plus build 4335,
- manageengine m365 manager plus build 4336,
- manageengine m365 manager plus build 4400,
- manageengine m365 manager plus build 4401,
- manageengine m365 manager plus build 4402,
- manageengine m365 manager plus build 4403,
- manageengine m365 manager plus build 4406,
- manageengine m365 manager plus build 4407,
- manageengine m365 manager plus build 4408,
- manageengine m365 manager plus build 4410,
- manageengine m365 manager plus build 4411,
- manageengine m365 manager plus build 4412,
- manageengine m365 manager plus build 4413,
- manageengine m365 manager plus build 4414,
- manageengine m365 manager plus build 4415,
- manageengine m365 manager plus build 4416,
- manageengine m365 manager plus build 4417,
- manageengine m365 manager plus build 4418,
- manageengine m365 manager plus build 4419
References
Miscellaneous
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: