ManageEngine Access Manager Plus Unauthenticated RCE (CVE-2022-47966)

critical Nessus Plugin ID 171707

Version 1.1

Feb 22, 2023, 2:14 PM

  • Exploit attributes ("Exploit available" set to "True". "Exploit available" set to "True". "Exploit available" set to "True". "Exploit available" set to "True". "Exploited by malware" set to "True". "Exploitability ease" set to "Exploits are available". "Exploit framework metasploit" set to "True". "Exploited by malware" set to "True". "Exploitability ease" set to "Exploits are available". "Exploit framework metasploit" set to "True". "Exploited by malware" set to "True". "Exploitability ease" set to "Exploits are available". "Exploit framework metasploit" set to "True")
  • CVSS metrics ("CVSSv2 score" changed from "7.5" to "10.0". "CVSSv2 score" changed from "7.5" to "10.0". "CVSSv2 score" changed from "7.5" to "10.0". "CVSSv2 score" changed from "7.5" to "10.0". "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P" to "CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C". "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P" to "CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C". "CVSSv2 vector" changed from "CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P" to "CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C". "CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C". "CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C". "CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C")

Plugin Feed: 202302221414