CISA: Napaka Zoho ManageEngine RCE se aktivno izkorišča PlatoBlockchain Data Intelligence. Navpično iskanje. Ai.

CISA: Napaka Zoho ManageEngine RCE se aktivno izkorišča

The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that a critical Zoho ManageEngine remote code execution (RCE) flaw, first disclosed in June, is now under active attack. 

According to Zoho’s patch advisory, the bug “could allow remote attackers to execute arbitrary code on affected installations.” 

Večkraten Zoho ManageEngine products are affected, CISA said, including the Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus. 

Authentication is not required to exploit the vulnerability in Password Manager Pro and PAM360 products, Zoho added.

CISA has moved to add the Zoho ManageEngine bug to the Known Exploited Vulnerabilities catalog, which indicates the bug (CVE-2022-35405) is both under active exploit and poses a threat to the federal government’s systems. 

CISA advises federal agencies to apply the vendor patch immediately. 

Spremljajte najnovejše grožnje kibernetske varnosti, na novo odkrite ranljivosti, informacije o kršitvah podatkov in nastajajoče trende. Dostavljeno dnevno ali tedensko neposredno v vaš e-poštni nabiralnik.

Časovni žig:

Več od Temno branje