← Vulnerability feed

Vulnerability record · CVE-2023-29084 · published 13 April 2023

CVE-2023-29084: Zoho ManageEngine ADManager Plus command injection via Proxy settings

Zohocorp · Manageengine Admanager Plus

Zoho ManageEngine ADManager Plus before build 7181 is vulnerable to command injection through the Proxy settings. An authenticated user with high privileges can inject OS commands that execute on the server. Because the affected component is an administrative configuration surface, successful exploitation can compromise the host running ADManager Plus.

7.2 CVSS 3.1 High EPSS 98% · top 0.1% CWE-77 · Command injection
7.2CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCVSS 7.2 with high confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires authenticated high privileges.

What it is

Zoho ManageEngine ADManager Plus before build 7181 is vulnerable to command injection through the Proxy settings. An authenticated user with high privileges can inject OS commands that execute on the server. Because the affected component is an administrative configuration surface, successful exploitation can compromise the host running ADManager Plus.

Impact

An attacker gains arbitrary command execution on the ADManager Plus server, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the management host and any credentials or directory data it handles.

Attack surface

The flaw is reachable over the network through the Proxy settings interface, per the CVSS vector AV:N. It requires high privileges (PR:H) and no user interaction (UI:N), so a valid administrative account is needed.

Exploitation

The record shows no CISA KEV listing and no ransomware association, but EPSS is very high at 0.98167 (99.9th percentile), indicating elevated likelihood of exploitation activity. A public Packet Storm reference exists, though it carries no exploit tag.

What to do

  • Upgrade ADManager Plus to build 7181 or later as the primary fix.
  • Restrict access to the ADManager Plus admin console and Proxy settings to trusted networks and accounts.
  • Enforce least privilege and review which accounts hold the high privileges required to reach the vulnerable setting.
  • Monitor and alert on unexpected outbound connections or process creation on the ADManager Plus host.

Detection

  • Review ADManager Plus logs for changes to Proxy settings and correlate with subsequent process execution on the host.
  • Hunt for anomalous child processes spawned by the ADManager Plus service or its web server.
  • Alert on unusual outbound network traffic originating from the ADManager Plus server.
  • Audit administrative account activity around the Proxy configuration for unexpected or off-hours changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29084 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-42002Zohocorp manageengine admanager plus vulnerabilityZoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.EPSS 7.5%9.8CVE-2021-38298Zohocorp manageengine admanager plus xml external entity (xxe) vulnerabilityZoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.EPSS 2.6%9.8CVE-2021-37762Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.EPSS 8.1%9.8CVE-2021-37918Zoho ManageEngine ADManager Plus unrestricted file upload RCEZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload, which leads to remote code execution. The flaw is rated CVSS…EPSS 74%analysed9.8CVE-2021-37919Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%9.8CVE-2021-37920Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%9.8CVE-2021-37921Zohocorp manageengine admanager plus unrestricted file upload vulnerabilityZoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2023-29084), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.