CVE-2021-20108 is a memory leak vulnerability affecting ManageEngine Asset Explorer Agent 1.0.34. An unauthenticated remote attacker can exploit this by repeatedly sending commands over HTTPS to port 9000, even without valid authentication, due to unverified certificates. This leads to an out-of-memory condition and a Denial of Service (DoS) for the agent. The vulnerability has a CVSS score of 7.5 (High) due to its network attack vector and high impact on availability. There is currently no public exploit code available, and it has not been observed in active exploitation or garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.34CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_assetexplorer:1.0.34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Manage Engine Asset Explorer Agent - Remote DoS
Jul 16, 2021Manage Engine Asset Explorer Agent - Remote DoS
Jul 16, 2021Manage Engine Asset Explorer Agent - Remote DoS
Jul 16, 2021Manage Engine Asset Explorer Agent - Remote DoS
Jul 16, 2021Manage Engine Asset Explorer Agent - Remote DoS
Jul 16, 2021