Impact
Unprotected agent API calls in ManageEngine ADAudit Plus allow unauthenticated users to inject and execute arbitrary OS commands. The flaw is an instance of command injection, giving attackers full control over the affected host and potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
Zohocorp’s ManageEngine ADAudit Plus, versions prior to 8606. The vulnerability affects the agent API exposed by these versions.
Risk and Exploitability
The CVSS score of 10 indicates critical severity, and the EPSS score of 5% suggests a moderate probability of real‑world exploitation. The flaw is not yet listed in CISA’s KEV catalog, but the lack of authentication and remote access via the API make it a high‑risk target for attackers.
OpenCVE Enrichment