CVE-2026-92905: 
Zoho ManageEngine EventLog Analyzer 脆弱性の分析と軽減

概要

CVE-2026-92905 is a denial-of-service (DoS) vulnerability in the log collector component of ZohoCorp ManageEngine EventLog Analyzer and Log360. Malformed syslog datagrams sent to the syslog listener port are not handled correctly, causing the collector service to crash unexpectedly. All builds prior to 13071 are affected; the vulnerability was disclosed and patched on August 25, 2026, with the advisory published September 24, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (ManageEngine Advisory, GitHub Advisory).

技術的な詳細

The root cause is an uncaught exception (CWE-248) in the syslog listener of the log collector component, where malformed syslog datagrams are not discarded safely and instead cause the service to terminate. An unauthenticated, network-adjacent attacker can send specially crafted malformed syslog packets to the syslog listener port without any credentials or user interaction required. The fix improves input validation so that malformed datagrams are silently discarded and the service continues running (ManageEngine Advisory, GitHub Advisory).

影響

Successful exploitation causes the log collector service to crash, interrupting syslog collection until the service is restarted or the patch is applied. There is no confidentiality or integrity impact — the vulnerability is limited to availability. In environments relying on EventLog Analyzer or Log360 for security monitoring and compliance, a sustained attack could create blind spots in log visibility, potentially masking other malicious activity (ManageEngine Advisory).

エクスプロイト可能性

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.0235, indicating a low probability of exploitation in the near term. Notably, the attack is automatable and requires no authentication, meaning a low-skilled attacker could trigger the DoS with minimal effort (GitHub Advisory, ManageEngine Advisory).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify hosts running ManageEngine EventLog Analyzer or Log360 (builds prior to 13071) with their syslog listener port exposed on the network (typically UDP/514 or a configured alternative).
  2. Craft malformed syslog packet: Construct a UDP datagram that violates the syslog protocol format (e.g., invalid priority field, oversized header, or malformed structured data) intended to trigger an uncaught exception in the log collector.
  3. Send packet to syslog listener: Transmit the malformed datagram to the target's syslog listener port using standard network tools (e.g., netcat, scapy, or a custom script).
  4. Crash the log collector: The unhandled exception causes the log collector service to stop unexpectedly, interrupting syslog ingestion until the service is manually restarted or the patch is applied (ManageEngine Advisory).

妥協の兆候

  • Network: Unexpected or malformed UDP packets arriving at the syslog listener port (typically UDP/514) from untrusted or external sources; high-volume syslog traffic from a single source IP.
  • Logs: Sudden absence of syslog ingestion events in EventLog Analyzer or Log360; service crash or restart entries in the application or system event logs around the time of the attack.
  • Process: Unexpected termination or restart of the log collector service process; crash dump files generated by the ManageEngine log collector component.

軽減策と回避策

ZohoCorp has addressed the vulnerability in build 13071, released August 25, 2026. Users should update EventLog Analyzer and Log360 to build 13071 or later using the official service pack links provided by ManageEngine. As a network-level workaround, restrict access to the syslog listener port to only trusted, known syslog sources using firewall rules or network ACLs, and monitor for anomalous syslog traffic patterns (ManageEngine Advisory).

コミュニティの反応

The vulnerability was discovered by a researcher named Seth through the Zoho Bug Bounty Program and responsibly disclosed to ZohoCorp. No significant public commentary, media coverage, or notable researcher reactions beyond the vendor advisory have been observed at this time (ManageEngine Advisory).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 Zoho ManageEngine EventLog Analyzer 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2021-44228CRITICAL10
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:cisco:sd-wan_vmanage
はいはいDec 10, 2021
CVE-2023-35785HIGH8.1
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
いいえはいAug 28, 2023
CVE-2021-44832MEDIUM6.6
  • IBM Db2 logoIBM Db2
  • hive-container-v4.8.0
いいえはいDec 28, 2021
CVE-2021-45105MEDIUM5.9
  • IBM Db2 logoIBM Db2
  • openshift4::ose-logging-elasticsearch6@sha256:f1a53e3be27c714226869b259c8eed80ac797b0cb83fbc2d786a9bba383d9547_amd64
いいえはいDec 18, 2021
CVE-2026-92905MEDIUM5.3
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer
いいえはいSep 24, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者