8.8

CVE-2022-29457

Exploit

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Adaudit Plus Version < 7.0.0
ZohocorpManageengine Adaudit Plus Version7.0.0 Update-
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7000
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7002
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7003
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7004
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7005
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7006
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7007
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7008
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7050
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7051
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7052
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7053
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7054
ZohocorpManageengine Adaudit Plus Version7.0.0 Update7055
ZohocorpManageengine Admanager Plus Version7.1 Update-
ZohocorpManageengine Admanager Plus Version7.1 Update7100
ZohocorpManageengine Admanager Plus Version7.1 Update7101
ZohocorpManageengine Admanager Plus Version7.1 Update7102
ZohocorpManageengine Admanager Plus Version7.1 Update7110
ZohocorpManageengine Admanager Plus Version7.1 Update7111
ZohocorpManageengine Admanager Plus Version7.1 Update7112
ZohocorpManageengine Admanager Plus Version7.1 Update7113
ZohocorpManageengine Admanager Plus Version7.1 Update7114
ZohocorpManageengine Admanager Plus Version7.1 Update7115
ZohocorpManageengine Admanager Plus Version7.1 Update7116
ZohocorpManageengine Admanager Plus Version7.1 Update7117
ZohocorpManageengine Admanager Plus Version7.1 Update7118
ZohocorpManageengine Admanager Plus Version7.1 Update7120
ZohocorpManageengine Admanager Plus Version7.1 Update7121
ZohocorpManageengine Admanager Plus Version7.1 Update7122
ZohocorpManageengine Admanager Plus Version7.1 Update7123
ZohocorpManageengine Admanager Plus Version7.1 Update7124
ZohocorpManageengine Admanager Plus Version7.1 Update7125
ZohocorpManageengine Admanager Plus Version7.1 Update7126
ZohocorpManageengine Admanager Plus Version7.1 Update7130
ZohocorpManageengine Adselfservice Plus Version6.1 Update-
ZohocorpManageengine Adselfservice Plus Version6.1 Update6100
ZohocorpManageengine Adselfservice Plus Version6.1 Update6101
ZohocorpManageengine Adselfservice Plus Version6.1 Update6102
ZohocorpManageengine Adselfservice Plus Version6.1 Update6103
ZohocorpManageengine Adselfservice Plus Version6.1 Update6104
ZohocorpManageengine Adselfservice Plus Version6.1 Update6105
ZohocorpManageengine Adselfservice Plus Version6.1 Update6106
ZohocorpManageengine Adselfservice Plus Version6.1 Update6107
ZohocorpManageengine Adselfservice Plus Version6.1 Update6108
ZohocorpManageengine Adselfservice Plus Version6.1 Update6109
ZohocorpManageengine Adselfservice Plus Version6.1 Update6110
ZohocorpManageengine Adselfservice Plus Version6.1 Update6111
ZohocorpManageengine Adselfservice Plus Version6.1 Update6112
ZohocorpManageengine Adselfservice Plus Version6.1 Update6113
ZohocorpManageengine Adselfservice Plus Version6.1 Update6114
ZohocorpManageengine Adselfservice Plus Version6.1 Update6115
ZohocorpManageengine Adselfservice Plus Version6.1 Update6116
ZohocorpManageengine Adselfservice Plus Version6.1 Update6117
ZohocorpManageengine Adselfservice Plus Version6.1 Update6118
ZohocorpManageengine Adselfservice Plus Version6.1 Update6119
ZohocorpManageengine Adselfservice Plus Version6.1 Update6120
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5700
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.66% 0.909
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.