Impact
The vulnerability allows an attacker to inject arbitrary shell commands through the Diagnose Settings feature, resulting in full remote code execution on the underlying system. It is a classic command injection flaw identified as CWE-78, where untrusted input is incorporated into system command execution without proper sanitization.
Affected Systems
ZohoCorp’s ManageEngine Firewall Analyzer and ManageEngine OpManager versions 12.8.709 and earlier are susceptible to the flaw. The issue is documented by the vendor on the ManageEngine advisory page.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, indicating a significant impact if successfully exploited. The EPSS value is not available, but the high CVSS suggests that a determined attacker may attempt exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the lack of public exploitation does not diminish the risk. It is inferred that the attack vector is web‑based, requiring access to the Diagnose Settings function, which normally permits only users with administrative privileges. An attacker who obtains such privileges could execute arbitrary commands on the host.
OpenCVE Enrichment