9.8

CVE-2021-40539

Warnung
Exploit
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update -
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6100
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6101
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6102
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6103
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6104
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6105
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6106
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6113

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Schwachstelle

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 98.96% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

https://www.manageengine.com
Product
http://packetstormsecurity.com/files/165085/ManageEngine-ADSelfService-Plus-Authentication-Bypass-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40539
US Government Resource