Caitlin Condon · @catc0n
675 followers · 155 posts · Server infosec.exchange

Absolutely stellar root cause analysis of ManageEngine from
@iagox86 and new Rapid7 research team member Stephen Fewer. TL;DR = exploitation not equally trivial across all affected products. There are also a number of vulns at play, two of which are from years and years ago. attackerkb.com/topics/gvs0Gv8B

#cve_2022_47966

Last updated 2 years ago

Caitlin Condon · @catc0n
675 followers · 155 posts · Server infosec.exchange

Absolutely stellar root cause analysis of ManageEngine from
@iagox86
and new Rapid7 research team member Stephen Fewer. TL;DR = exploitation not equally trivial across all affected products. There are also a number of vulns at play, two of which are from years and years ago. attackerkb.com/topics/gvs0Gv8B

#cve_2022_47966

Last updated 2 years ago

Ron Bowes · @iagox86
1002 followers · 208 posts · Server infosec.exchange

I just posted our technical analysis of the recent vulnerability in - CVE-2022-47966 ( / . Big thanks to @catc0n and my new co-worker @stephenfewer@twitter.com for their help on this one!

attackerkb.com/topics/gvs0Gv8B

#rapid7 #manageengine #cve202247966 #cve_2022_47966

Last updated 2 years ago

remy🐀 · @_mattata
862 followers · 127 posts · Server infosec.exchange

PoC and analysis for CVE-2022-47966 Zoho ManageEngine pre-authentication remote code execution vulnerability has been published.
GreyNoise tag for tracking related activity is live and available to all users.
viz.greynoise.io/tag/zoho-mana
horizon3.ai/manageengine-cve-2

#cve_2022_47966

Last updated 2 years ago