← KEV catalog
CISA known exploited vulnerability

CVE-2022-35405

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

SOURCE FACT

Zoho · ManageEngine

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

Required action

Apply updates per vendor instructions.

CISA notes

https://www.manageengine.com/products/passwordmanagerpro/advisory/cve-2022-35405.html; https://nvd.nist.gov/vuln/detail/CVE-2022-35405

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?