Vulnerability record · CVE-2023-29084 · published 13 April 2023
CVE-2023-29084: Zoho ManageEngine ADManager Plus command injection via Proxy settings
Zohocorp · Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus before build 7181 is vulnerable to command injection through the Proxy settings. An authenticated user with high privileges can inject OS commands that execute on the server. Because the affected component is an administrative configuration surface, successful exploitation can compromise the host running ADManager Plus.
Description
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires authenticated high privileges.
What it is
Zoho ManageEngine ADManager Plus before build 7181 is vulnerable to command injection through the Proxy settings. An authenticated user with high privileges can inject OS commands that execute on the server. Because the affected component is an administrative configuration surface, successful exploitation can compromise the host running ADManager Plus.
Impact
An attacker gains arbitrary command execution on the ADManager Plus server, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the management host and any credentials or directory data it handles.
Attack surface
The flaw is reachable over the network through the Proxy settings interface, per the CVSS vector AV:N. It requires high privileges (PR:H) and no user interaction (UI:N), so a valid administrative account is needed.
Exploitation
The record shows no CISA KEV listing and no ransomware association, but EPSS is very high at 0.98167 (99.9th percentile), indicating elevated likelihood of exploitation activity. A public Packet Storm reference exists, though it carries no exploit tag.
What to do
- Upgrade ADManager Plus to build 7181 or later as the primary fix.
- Restrict access to the ADManager Plus admin console and Proxy settings to trusted networks and accounts.
- Enforce least privilege and review which accounts hold the high privileges required to reach the vulnerable setting.
- Monitor and alert on unexpected outbound connections or process creation on the ADManager Plus host.
Detection
- Review ADManager Plus logs for changes to Proxy settings and correlate with subsequent process execution on the host.
- Hunt for anomalous child processes spawned by the ADManager Plus service or its web server.
- Alert on unusual outbound network traffic originating from the ADManager Plus server.
- Audit administrative account activity around the Proxy configuration for unexpected or off-hours changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-29084 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-29084), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.