Cyber Resilience

CVE-2023-31099

Zohocorp Manageengine Opmanager ≤ 12.6

High EPSS
Published
04 May 2023
Modified
29 January 2025
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.82 99.6th percentile
Risk Priority 90 floored blend · peak EPSS

Summary

CVE-2023-31099 is a high-severity an unspecified weakness vulnerability in Zohocorp Manageengine Opmanager. Its CVSS base score is 8.8 (High).

Operationally, ranked in the top 0.4% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Zoho ManageEngine OPManager through version 126323 contains a remote code execution vulnerability that can be triggered through its probe servers. The flaw carries a CVSS 3.1 score of 8.8 and is reachable over the network by any authenticated user without additional user interaction.

An authenticated attacker can leverage the issue to execute arbitrary code on the affected server, resulting in full compromise of confidentiality, integrity, and availability. No special privileges beyond standard authenticated access are required.

Official guidance is available from the vendor at https://www.manageengine.com/network-monitoring/security-updates/cve-2023-31099.html, which directs customers to apply the listed security updates for OPManager.

EPSS for the CVE reached a peak of 0.8494 on 2026-04-16 before receding to the current value of 0.5823, indicating sustained post-disclosure exploitation interest.

EU & UK References

Vulnerability Data

Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.

CWE(s)

Related Threats

CVEs Like This One

CVE-2019-17602Same product: Zohocorp Manageengine Opmanager
CVE-2021-40493Same product: Zohocorp Manageengine Opmanager
CVE-2021-20078Same product: Zohocorp Manageengine Opmanager
CVE-2020-28653Same product: Zohocorp Manageengine Opmanager
CVE-2022-29535Same product: Zohocorp Manageengine Opmanager
CVE-2018-17243Same product: Zohocorp Manageengine Opmanager
CVE-2021-3287Same product: Zohocorp Manageengine Opmanager
CVE-2021-41288Same product: Zohocorp Manageengine Opmanager
CVE-2024-5466Same product: Zohocorp Manageengine Opmanager
CVE-2022-38772Same product: Zohocorp Manageengine Opmanager

Affected Assets

zohocorp
manageengine opmanager
12.6 · ≤ 12.6

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References