HTTP: Zoho ManageEngine RecoveryManager Plus updateProxySettings Command Injection

This signature detects attempts to exploit a known vulnerability against Zoho ManageEngine RecoveryManager Plus. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.

Affected Products

Zohocorp manageengine_recoverymanager_plus

Short Name
HTTP:CTS:ZOHO-RECVR-MNG-CMD-INJ
Severity
Major
Recommended
True
Recommended Action
None
Category
HTTP
Keywords
CVE-2023-48646 Command Injection ManageEngine Plus RecoveryManager Zoho updateProxySettings
Release Date
01/05/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3667
False Positive
Unknown
Vendors

Zohocorp

Found a potential security threat?