« Volver al listado

CVE-2021-28959

Estado: ModificadaCrítica (9.8)—

Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-28959",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-04-30T13:15:07.470",
  "references": [
    {
      "url": "https://www.manageengine.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.manageengine.com/products/eventlog/features-new.html#release",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.manageengine.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.manageengine.com/products/eventlog/features-new.html#release",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution."
    },
    {
      "lang": "es",
      "value": "Zoho ManageEngine Eventlog Analyzer versiones hasta 12147, es vulnerable al salto de directorio no autenticado por medio de una entrada en un archivo ZIP. Esto conlleva a una ejecución de código remota."
    }
  ],
  "lastModified": "2026-06-17T03:47:05.063",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2F75F95-CF32-458C-9CE0-894CFAB78B06",
              "versionEndExcluding": "12.1.4"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer:12.1.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5B8AC3F-AAB3-44BC-A89D-2C3D8DE12354"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer:12.1.4:12141:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACFD1173-F12C-4218-9F3C-28F6099E3BE8"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer:12.1.4:12145:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB7893F8-40B7-41E1-AB1B-93D6EA82DF4A"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer:12.1.4:12146:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "284715B5-556F-495E-A44C-0C1E8A5B89B0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}