Impact
The vulnerability resides in the Notification Profile module of ManageEngine OpManager, allowing an attacker to execute arbitrary code remotely. Classified as CWE-78, it reveals that command injection can occur. If successfully exploited, an attacker could achieve full control of the affected system, enabling modification, deletion, or exfiltration of data.
Affected Systems
Zohocorp ManageEngine OpManager MSP versions 12.8.709 and older are affected. The flaw exists in the Notification Profile module and applies to all installations running those versions.
Risk and Exploitability
The CVSS score of 9.9 denotes critical severity; the EPSS score is not available, so the exact exploitation probability remains unknown. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires sending specially crafted requests to the Notification Profile module; the description does not mention authentication bypass, so it is inferred that the attacker needs network access to the server. The high severity combined with remote nature indicates a high risk of severe compromise.
OpenCVE Enrichment