Impact
The vulnerability is a server‑side template injection in Configlet processing that allows an attacker to execute arbitrary code on the host, compromising confidentiality, integrity, and availability of the affected systems.
Affected Systems
Zohocorp’s ManageEngine products—NetFlow Analyzer, Network Configuration Manager, and OpManager—are impacted when running version 12.8.667 or earlier.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, but the EPSS score is unavailable, so the likelihood of exploitation is uncertain. Because the flaw occurs during Configlet processing, the likely attack vector is remote via crafted requests to the application’s template engine.
OpenCVE Enrichment