CVE-2021-20109 is a heap overflow vulnerability in ZohoCorp ManageEngine Asset Explorer, specifically within the Asset Explorer agent. An attacker on the network can exploit this by impersonating the Asset Explorer server due to a lack of HTTPS certificate validation, sending a crafted NEWSCAN request to an agent. This can lead to a heap overflow if the agent's HTTP POST payload response exceeds a 0x2000 byte buffer when converted to Unicode. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity, no privileges or user interaction required, and a high impact on integrity, though confidentiality and availability are not directly impacted. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.34CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_assetexplorer:1.0.34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Manage Engine Heap Overflow POST payload
Jul 16, 2021Manage Engine Heap Overflow POST payload
Jul 16, 2021Manage Engine Heap Overflow POST payload
Jul 16, 2021Manage Engine Heap Overflow POST payload
Jul 16, 2021Manage Engine Heap Overflow POST payload
Jul 16, 2021