Check Point Advisories

Zoho ManageEngine OPManager Remote Code Execution (CVE-2023-31099)

Check Point Reference: CPAI-2023-2577
Date Published: 16 Nov 2025
Severity: High
Last Updated: Sunday 16 November, 2025
Source:
Industry Reference:CVE-2023-31099
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Zoho ManageEngine OPManager prior to 12.6
Zoho ManageEngine OPManager 12.6 build126000
Zoho ManageEngine OPManager 12.6 build126001
Zoho ManageEngine OPManager 12.6 build126002
Zoho ManageEngine OPManager 12.6 build126004
Zoho ManageEngine OPManager 12.6 build126005
Zoho ManageEngine OPManager 12.6 build126100
Zoho ManageEngine OPManager 12.6 build126101
Zoho ManageEngine OPManager 12.6 build126102
Zoho ManageEngine OPManager 12.6 build126103
Zoho ManageEngine OPManager 12.6 build126104
Zoho ManageEngine OPManager 12.6 build126107
Zoho ManageEngine OPManager 12.6 build126108
Zoho ManageEngine OPManager 12.6 build126109
Zoho ManageEngine OPManager 12.6 build126110
Zoho ManageEngine OPManager 12.6 build126113
Zoho ManageEngine OPManager 12.6 build126114
Zoho ManageEngine OPManager 12.6 build126115
Zoho ManageEngine OPManager 12.6 build126116
Zoho ManageEngine OPManager 12.6 build126117
Zoho ManageEngine OPManager 12.6 build126118
Zoho ManageEngine OPManager 12.6 build126119
Zoho ManageEngine OPManager 12.6 build126120
Zoho ManageEngine OPManager 12.6 build126121
Zoho ManageEngine OPManager 12.6 build126122
Zoho ManageEngine OPManager 12.6 build126130
Zoho ManageEngine OPManager 12.6 build126131
Zoho ManageEngine OPManager 12.6 build126132
Zoho ManageEngine OPManager 12.6 build126134
Zoho ManageEngine OPManager 12.6 build126135
Zoho ManageEngine OPManager 12.6 build126136
Zoho ManageEngine OPManager 12.6 build126139
Zoho ManageEngine OPManager 12.6 build126141
Zoho ManageEngine OPManager 12.6 build126147
Zoho ManageEngine OPManager 12.6 build126148
Zoho ManageEngine OPManager 12.6 build126149
Zoho ManageEngine OPManager 12.6 build126150
Zoho ManageEngine OPManager 12.6 build126151
Zoho ManageEngine OPManager 12.6 build126154
Zoho ManageEngine OPManager 12.6 build126155
Zoho ManageEngine OPManager 12.6 build126162
Zoho ManageEngine OPManager 12.6 build126163
Zoho ManageEngine OPManager 12.6 build126164
Zoho ManageEngine OPManager 12.6 build126165
Zoho ManageEngine OPManager 12.6 build126166
Zoho ManageEngine OPManager 12.6 build126167
Zoho ManageEngine OPManager 12.6 build126168
Zoho ManageEngine OPManager 12.6 build126169
Zoho ManageEngine OPManager 12.6 build126262
Zoho ManageEngine OPManager 12.6 build126264
Zoho ManageEngine OPManager 12.6 build126275
Zoho ManageEngine OPManager 12.6 build126276
Zoho ManageEngine OPManager 12.6 build126277
Zoho ManageEngine OPManager 12.6 build126278
Zoho ManageEngine OPManager 12.6 build126279
Zoho ManageEngine OPManager 12.6 build126280
Zoho ManageEngine OPManager 12.6 build126283
Zoho ManageEngine OPManager 12.6 build126284
Zoho ManageEngine OPManager 12.6 build126285
Zoho ManageEngine OPManager 12.6 build126290
Zoho ManageEngine OPManager 12.6 build126293
Zoho ManageEngine OPManager 12.6 build126294
Zoho ManageEngine OPManager 12.6 build126295
Zoho ManageEngine OPManager 12.6 build126306
Zoho ManageEngine OPManager 12.6 build126308
Zoho ManageEngine OPManager 12.6 build126310
Vulnerability Description A remote code execution vulnerability in Zoho ManageEngine OPManager allows an authenticated user to achieve remote code execution via probe servers.

Protection Overview

This protection detects attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.

Security Gateway R81 / R80 / R77 / R75

  1. In the IPS tab, click Protections and find the Zoho ManageEngine OPManager Remote Code Execution (CVE-2023-31099) protection using the Search tool and Edit the protection's settings.
  2. Install policy on all Security Gateways.

This protection's log will contain the following information:

Attack Name:  Web Server Enforcement Violation.
Attack Information:  Zoho ManageEngine OPManager Remote Code Execution (CVE-2023-31099)

×
  Feedback
This website uses cookies for its functionality and for analytics and marketing purposes. By continuing to use this website, you agree to the use of cookies. For more information, please read our Cookies Notice.
OK