Vulnerability Intelligence Report
CVE-2019-17421
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
EPSS Probability:0.55%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| zohocorp | manageengine_firewall_analyzer | 12.4 |
| zohocorp | manageengine_opmanager | 12.4 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.554%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2019-10-09T00:00:00 |
| Published | 2019-11-21T14:36:02 |
| Last Updated | 2024-08-05T01:40:15 |
Community Chatter & Buzz