Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-20130

44
FAUCET Score

CVE-2021-20130 is a post-authentication remote code execution vulnerability affecting ManageEngine ADManager Plus Build 7111. It stems from improperly validated file uploads within the PasswordExpiry interface. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the network with low attack complexity, allowing an authenticated attacker to achieve full compromise of confidentiality, integrity, and availability. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.1CPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*
7.1CPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:-:*:*:*:*:*:*
7.1CPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7100:*:*:*:*:*:*
7.1CPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7101:*:*:*:*:*:*
7.1CPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7102:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
31.62%
Probability of exploitation in next 30 days
EPSS Percentile
98.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.3162 is in the 97th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (5)

asteriskvendor investigatingvia llm_extracted
ciscovendor investigatingvia llm_extracted
miniovendor investigatingvia llm_extracted
opensshvendor investigatingvia llm_extracted
railsvendor investigatingvia llm_extracted

Vendor Advisories (5)

opensshllm-openssh-b784d1eac2c8df7fHIGH

ManageEngine ADManager Plus Build 7111 Multiple Vulnerabilities

Oct 13, 2021
railsllm-rails-27a1adb97177cc90HIGH

ManageEngine ADManager Plus Build 7111 Multiple Vulnerabilities

Oct 13, 2021
miniollm-minio-ade21309ed69a0c1HIGH

ManageEngine ADManager Plus Build 7111 Multiple Vulnerabilities

Oct 13, 2021
ciscollm-cisco-dd163f6760d4834eHIGH

ManageEngine ADManager Plus Build 7111 Multiple Vulnerabilities

Oct 13, 2021
asteriskllm-asterisk-5a7d70158b4974e7HIGH

ManageEngine ADManager Plus Build 7111 Multiple Vulnerabilities

Oct 13, 2021

References

tenable.com / security/research/tra-2021-43
Vendor Advisory