CVE-2022-43473 is a blind XML External Entity (XXE) vulnerability in Zoho ManageEngine OpManager, OpManager MSP, and OpManager Plus, specifically within the "Add UCS Device" functionality. This vulnerability allows an unauthenticated attacker to trigger Server-Side Request Forgery (SSRF) by serving a specially crafted XML payload, with a CVSS score of 5.4 (Medium). While it has a low EPSS score and no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), there has been some community discussion on Reddit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.6CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:* | ||
12.6CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126000:*:*:*:*:*:* | ||
12.6CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126001:*:*:*:*:*:* | ||
12.6CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126002:*:*:*:*:*:* | ||
12.6CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126004:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.