Vulnerability record · CVE-2023-47211 · published 8 January 2024
CVE-2023-47211: ManageEngine OpManager uploadMib path traversal allows arbitrary file creation
Zohocorp · Manageengine Firewall Analyzer
The uploadMib function in ManageEngine OpManager 12.7.258 does not properly validate paths, so a crafted HTTP request carrying a malicious MIB file can write files to arbitrary locations. Because the write is unauthenticated and can reach outside the application's intended directory, it is a serious integrity risk for exposed instances.
Description
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Automated analysis
high priorityUnauthenticated network-reachable arbitrary file creation with a high EPSS score and public exploit detail, though not in KEV.
What it is
The uploadMib function in ManageEngine OpManager 12.7.258 does not properly validate paths, so a crafted HTTP request carrying a malicious MIB file can write files to arbitrary locations. Because the write is unauthenticated and can reach outside the application's intended directory, it is a serious integrity risk for exposed instances.
Impact
An attacker can create arbitrary files on the server, which can lead to code execution or configuration tampering depending on what the attacker can write and where. The CVSS vector shows high integrity impact with no confidentiality or availability impact.
Attack surface
Reachable over the network through the uploadMib HTTP endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description confirms the trigger is a malicious MIB file sent in a request.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.47 (98.8th percentile) and the Talos reference is tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.
What to do
- Apply the vendor fix referenced in the ManageEngine advisory for CVE-2023-47211.
- Restrict network access to the OpManager uploadMib endpoint to trusted management networks only.
- Run the product with least privilege so arbitrary file writes cannot reach sensitive paths.
- Audit file system changes in and around the OpManager installation for unexpected files.
- Monitor vendor advisories for the other listed ManageEngine products sharing this code path.
Detection
- Alert on HTTP requests to the uploadMib endpoint from untrusted sources.
- Monitor for new or modified files in web-accessible and application directories.
- Inspect MIB upload payloads for traversal sequences such as ../ in filenames.
- Correlate file creation events with OpManager process activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2023-1851 | ExploitThird Party Advisory |
| https://www.manageengine.com/itom/advisory/cve-2023-47211.html | Vendor Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2023-1851 | ExploitThird Party Advisory |
| https://www.manageengine.com/itom/advisory/cve-2023-47211.html | Vendor Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1851 |
Track CVE-2023-47211 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-47211), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.