Vulnerability record · CVE-2023-48646 · published 22 November 2023
CVE-2023-48646: ManageEngine RecoveryManager Plus proxy settings command injection
Zohocorp · Manageengine Recoverymanager Plus
Zoho ManageEngine RecoveryManager Plus before build 6070 lets admin users execute arbitrary commands through proxy settings. The flaw is a command injection reachable over the network, so a privileged account can turn configuration access into code execution on the server. It matters because administrative compromise of a backup/recovery tool can expose or destroy the very data it protects.
Description
Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires an existing admin account.
What it is
Zoho ManageEngine RecoveryManager Plus before build 6070 lets admin users execute arbitrary commands through proxy settings. The flaw is a command injection reachable over the network, so a privileged account can turn configuration access into code execution on the server. It matters because administrative compromise of a backup/recovery tool can expose or destroy the very data it protects.
Impact
An attacker with admin access gains arbitrary command execution on the RecoveryManager Plus host, allowing full compromise of that server and any credentials or backup data it holds.
Attack surface
Reached over the network via the application's proxy settings interface, per the CVSS vector AV:N. It requires high privileges (PR:H) and no user interaction (UI:N), so a valid admin account is needed.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high at 0.82 (99.6th percentile), indicating strong predicted exploitation activity.
What to do
- Upgrade RecoveryManager Plus to build 6070 or later, per the vendor advisory.
- Restrict network access to the RecoveryManager Plus admin interface to trusted management networks.
- Audit and minimize the number of accounts with administrative rights in the product.
- Review proxy settings for unexpected or injected values and reset them to known-good configuration.
- Monitor the host for unexpected child processes spawned by the application service.
Detection
- Alert on process creation where the RecoveryManager Plus service spawns command shells or system utilities.
- Monitor proxy configuration changes in the application and correlate them with process execution events.
- Review application and OS logs for command strings or unusual arguments tied to proxy setting updates.
- Track authentication and admin actions from unusual source IPs against the RecoveryManager Plus console.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com/ad-recovery-manager/advisory/CVE-2023-48646.html | Vendor Advisory |
| https://www.manageengine.com/ad-recovery-manager/advisory/CVE-2023-48646.html | Vendor Advisory |
Track CVE-2023-48646 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-48646), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.