CVE-2019-17421 is a privilege escalation vulnerability affecting Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 due to incorrect file permissions on the packaged Nipper executable. A local attacker can overwrite this file with a malicious payload to achieve root privileges. This vulnerability has a CVSS score of 7.8 (High), indicating high impact on confidentiality, integrity, and availability with low attack complexity and no user interaction. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion, including a Reddit writeup.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.4CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.4:124072:*:*:*:*:*:* | ||
12.4CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124072:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.