CRITICAL

CVE-2021-20078

CVSS v3

9.1

CRITICAL

EPSS Score

55.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

Technical details

Published
4/1/2021

Frequently asked questions

What is CVE-2021-20078?

Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

Is CVE-2021-20078 actively exploited?

Active exploitation of CVE-2021-20078 has not been confirmed. The EPSS score is 55.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-20078?

CVE-2021-20078 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2021-20078 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.