7.1

CVE-2022-28810

Warnung
Exploit
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update -
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6100
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6101
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6102
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6103
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6104
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6105
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6106
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6107
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6108
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6109
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6110
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6111
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6112
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6113
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6114
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6115
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6116
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6117
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6118
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6119
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6120
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.1 Update 6121

07.03.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Schwachstelle

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 70.97% 0.993
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 0.9 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
NIST 7.1 3.9 10
AV:N/AC:H/Au:S/C:C/I:C/A:C
CISA-ADP 6.8 0.9 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

http://packetstormsecurity.com/files/166816/ManageEngine-ADSelfService-Plus-Custom-Script-Execution.html
Third Party Advisory
Exploit
VDB Entry
https://github.com/rapid7/metasploit-framework/pull/16475
Patch
Third Party Advisory
Exploit
https://www.manageengine.com/products/self-service-password/kb/cve-2022-28810.html
Patch
Vendor Advisory
https://www.rapid7.com/blog/post/2022/04/14/cve-2022-28810-manageengine-adselfservice-plus-authenticated-command-execution-fixed/
Patch
Third Party Advisory
Exploit
Technical Description
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-28810
US Government Resource