Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-20109

24
FAUCET Score

CVE-2021-20109 is a heap overflow vulnerability in ZohoCorp ManageEngine Asset Explorer, specifically within the Asset Explorer agent. An attacker on the network can exploit this by impersonating the Asset Explorer server due to a lack of HTTPS certificate validation, sending a crafted NEWSCAN request to an agent. This can lead to a heap overflow if the agent's HTTP POST payload response exceeds a 0x2000 byte buffer when converted to Unicode. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity, no privileges or user interaction required, and a high impact on integrity, though confidentiality and availability are not directly impacted. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.0.34CPE matchmatch criteria
cpe:2.3:a:zohocorp:manageengine_assetexplorer:1.0.34:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.38%
Probability of exploitation in next 30 days
EPSS Percentile
69.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0138 is in the 50th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (5)

asteriskvendor investigatingvia llm_extracted
ciscovendor investigatingvia llm_extracted
miniovendor investigatingvia llm_extracted
opensshvendor investigatingvia llm_extracted
railsvendor investigatingvia llm_extracted

Vendor Advisories (5)

opensshllm-openssh-1c13cc6ac8e2e898HIGH

Manage Engine Heap Overflow POST payload

Jul 16, 2021
railsllm-rails-667c9663d7a8b9f6HIGH

Manage Engine Heap Overflow POST payload

Jul 16, 2021
miniollm-minio-2deab2db39289e14HIGH

Manage Engine Heap Overflow POST payload

Jul 16, 2021
ciscollm-cisco-c7ac9dd2f47d3b24HIGH

Manage Engine Heap Overflow POST payload

Jul 16, 2021
asteriskllm-asterisk-69c5ec0684125d9bHIGH

Manage Engine Heap Overflow POST payload

Jul 16, 2021

References

tenable.com / security/research/tra-2021-30
Third Party Advisory