8.1

CVE-2023-35785

Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360 UEBA 4045 and below, M365 Manager Plus 4529 and below, M365 Security Plus 4529 and below, Recovery Manager Plus 6061 and below, ServiceDesk Plus 14204 and below and 143xx 14302 and below, ServiceDesk Plus MSP 14300 and below, SharePoint Manager Plus 4402 and below, and Support Center Plus 14300 and below are vulnerable to 2FA bypass via a few TOTP authenticators. Note: A valid pair of username and password is required to leverage this vulnerability.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Ad360 Version < 4.3
ZohocorpManageengine Ad360 Version4.3 Update4300
ZohocorpManageengine Ad360 Version4.3 Update4302
ZohocorpManageengine Ad360 Version4.3 Update4303
ZohocorpManageengine Ad360 Version4.3 Update4304
ZohocorpManageengine Ad360 Version4.3 Update4305
ZohocorpManageengine Ad360 Version4.3 Update4306
ZohocorpManageengine Ad360 Version4.3 Update4308
ZohocorpManageengine Ad360 Version4.3 Update4309
ZohocorpManageengine Ad360 Version4.3 Update4310
ZohocorpManageengine Ad360 Version4.3 Update4312
ZohocorpManageengine Ad360 Version4.3 Update4313
ZohocorpManageengine Ad360 Version4.3 Update4314
ZohocorpManageengine Ad360 Version4.3 Update4315
ZohocorpManageengine Adaudit Plus Version7.2 Update7200
ZohocorpManageengine Adaudit Plus Version7.2 Update7201
ZohocorpManageengine Adaudit Plus Version7.2 Update7202
ZohocorpManageengine Admanager Plus Version7.2 Update7201
ZohocorpManageengine Assetexplorer Version6.9 Update-
ZohocorpManageengine Assetexplorer Version6.9 Update6900
ZohocorpManageengine Assetexplorer Version6.9 Update6901
ZohocorpManageengine Assetexplorer Version6.9 Update6902
ZohocorpManageengine Assetexplorer Version6.9 Update6903
ZohocorpManageengine Assetexplorer Version6.9 Update6904
ZohocorpManageengine Assetexplorer Version6.9 Update6905
ZohocorpManageengine Assetexplorer Version6.9 Update6906
ZohocorpManageengine Assetexplorer Version6.9 Update6907
ZohocorpManageengine Assetexplorer Version6.9 Update6908
ZohocorpManageengine Assetexplorer Version6.9 Update6909
ZohocorpManageengine Assetexplorer Version6.9 Update6950
ZohocorpManageengine Assetexplorer Version6.9 Update6951
ZohocorpManageengine Assetexplorer Version6.9 Update6952
ZohocorpManageengine Assetexplorer Version6.9 Update6953
ZohocorpManageengine Assetexplorer Version6.9 Update6954
ZohocorpManageengine Assetexplorer Version6.9 Update6955
ZohocorpManageengine Assetexplorer Version6.9 Update6956
ZohocorpManageengine Assetexplorer Version6.9 Update6957
ZohocorpManageengine Assetexplorer Version6.9 Update6970
ZohocorpManageengine Assetexplorer Version6.9 Update6971
ZohocorpManageengine Assetexplorer Version6.9 Update6972
ZohocorpManageengine Assetexplorer Version6.9 Update6973
ZohocorpManageengine Assetexplorer Version6.9 Update6974
ZohocorpManageengine Assetexplorer Version6.9 Update6975
ZohocorpManageengine Assetexplorer Version6.9 Update6976
ZohocorpManageengine Assetexplorer Version6.9 Update6977
ZohocorpManageengine Assetexplorer Version6.9 Update6978
ZohocorpManageengine Assetexplorer Version6.9 Update6979
ZohocorpManageengine Assetexplorer Version6.9 Update6980
ZohocorpManageengine Assetexplorer Version6.9 Update6981
ZohocorpManageengine Assetexplorer Version6.9 Update6982
ZohocorpManageengine Assetexplorer Version6.9 Update6983
ZohocorpManageengine Assetexplorer Version6.9 Update6984
ZohocorpManageengine Assetexplorer Version6.9 Update6985
ZohocorpManageengine Assetexplorer Version6.9 Update6986
ZohocorpManageengine Assetexplorer Version6.9 Update6987
ZohocorpManageengine Assetexplorer Version6.9 Update6988
ZohocorpManageengine Assetexplorer Version6.9 Update6989
ZohocorpManageengine Assetexplorer Version6.9 Update6990
ZohocorpManageengine Assetexplorer Version6.9 Update6991
ZohocorpManageengine Assetexplorer Version6.9 Update6992
ZohocorpManageengine Assetexplorer Version6.9 Update6993
ZohocorpManageengine Assetexplorer Version7.0 Update7000
ZohocorpManageengine Assetexplorer Version7.0 Update7001
ZohocorpManageengine Cloud Security Plus Version4.1 Update4100
ZohocorpManageengine Cloud Security Plus Version4.1 Update4101
ZohocorpManageengine Cloud Security Plus Version4.1 Update4102
ZohocorpManageengine Cloud Security Plus Version4.1 Update4103
ZohocorpManageengine Cloud Security Plus Version4.1 Update4104
ZohocorpManageengine Cloud Security Plus Version4.1 Update4105
ZohocorpManageengine Cloud Security Plus Version4.1 Update4106
ZohocorpManageengine Cloud Security Plus Version4.1 Update4107
ZohocorpManageengine Cloud Security Plus Version4.1 Update4108
ZohocorpManageengine Cloud Security Plus Version4.1 Update4109
ZohocorpManageengine Cloud Security Plus Version4.1 Update4110
ZohocorpManageengine Cloud Security Plus Version4.1 Update4111
ZohocorpManageengine Cloud Security Plus Version4.1 Update4112
ZohocorpManageengine Cloud Security Plus Version4.1 Update4113
ZohocorpManageengine Cloud Security Plus Version4.1 Update4115
ZohocorpManageengine Cloud Security Plus Version4.1 Update4116
ZohocorpManageengine Cloud Security Plus Version4.1 Update4117
ZohocorpManageengine Cloud Security Plus Version4.1 Update4118
ZohocorpManageengine Cloud Security Plus Version4.1 Update4119
ZohocorpManageengine Cloud Security Plus Version4.1 Update4120
ZohocorpManageengine Cloud Security Plus Version4.1 Update4121
ZohocorpManageengine Cloud Security Plus Version4.1 Update4122
ZohocorpManageengine Cloud Security Plus Version4.1 Update4130
ZohocorpManageengine Cloud Security Plus Version4.1 Update4131
ZohocorpManageengine Cloud Security Plus Version4.1 Update4140
ZohocorpManageengine Cloud Security Plus Version4.1 Update4141
ZohocorpManageengine Cloud Security Plus Version4.1 Update4150
ZohocorpManageengine Cloud Security Plus Version4.1 Update4160
ZohocorpManageengine Cloud Security Plus Version4.1 Update4161
ZohocorpManageengine Datasecurity Plus Version6.1 Update6100
ZohocorpManageengine Datasecurity Plus Version6.1 Update6101
ZohocorpManageengine Datasecurity Plus Version6.1 Update6110
ZohocorpManageengine Eventlog Analyzer Version12.3.0 Update12300
ZohocorpManageengine Eventlog Analyzer Version12.3.0 Update12301
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5700
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5701
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5702
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5703
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5704
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5705
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5706
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5707
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5708
ZohocorpManageengine Exchange Reporter Plus Version5.7 Update5709
ZohocorpManageengine Log360 Version < 5.3
ZohocorpManageengine Log360 Version5.3 Updatebuild5300
ZohocorpManageengine Log360 Version5.3 Updatebuild5301
ZohocorpManageengine Log360 Version5.3 Updatebuild5302
ZohocorpManageengine Log360 Version5.3 Updatebuild5305
ZohocorpManageengine Log360 Version5.3 Updatebuild5310
ZohocorpManageengine Log360 Version5.3 Updatebuild5311
ZohocorpManageengine Log360 Version5.3 Updatebuild5315
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4010
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4011
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4015
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4016
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4020
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4021
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4023
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4024
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4025
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4026
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4027
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4028
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4030
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4031
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4034
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4035
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4036
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4040
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4043
ZohocorpManageengine Log360 Ueba Version4.0 Updatebuild4045
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4500
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4502
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4503
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4504
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4505
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4507
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4508
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4509
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4510
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4511
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4512
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4513
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4514
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4516
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4517
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4518
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4519
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4520
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4523
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4525
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4527
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4528
ZohocorpManageengine M365 Manager Plus Version4.5 Updatebuild4529
ZohocorpManageengine M365 Security Plus Version4.5 Update4500
ZohocorpManageengine M365 Security Plus Version4.5 Update4502
ZohocorpManageengine M365 Security Plus Version4.5 Update4503
ZohocorpManageengine M365 Security Plus Version4.5 Update4504
ZohocorpManageengine M365 Security Plus Version4.5 Update4505
ZohocorpManageengine M365 Security Plus Version4.5 Update4507
ZohocorpManageengine M365 Security Plus Version4.5 Update4508
ZohocorpManageengine M365 Security Plus Version4.5 Update4509
ZohocorpManageengine M365 Security Plus Version4.5 Update4510
ZohocorpManageengine M365 Security Plus Version4.5 Update4511
ZohocorpManageengine M365 Security Plus Version4.5 Update4512
ZohocorpManageengine M365 Security Plus Version4.5 Update4513
ZohocorpManageengine M365 Security Plus Version4.5 Update4514
ZohocorpManageengine M365 Security Plus Version4.5 Update4516
ZohocorpManageengine M365 Security Plus Version4.5 Update4517
ZohocorpManageengine M365 Security Plus Version4.5 Update4518
ZohocorpManageengine M365 Security Plus Version4.5 Update4519
ZohocorpManageengine M365 Security Plus Version4.5 Update4520
ZohocorpManageengine M365 Security Plus Version4.5 Update4523
ZohocorpManageengine M365 Security Plus Version4.5 Update4525
ZohocorpManageengine M365 Security Plus Version4.5 Update4527
ZohocorpManageengine M365 Security Plus Version4.5 Update4528
ZohocorpManageengine M365 Security Plus Version4.5 Update4529
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6001
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6003
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6005
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6011
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6016
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6017
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6020
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6025
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6026
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6030
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6031
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6032
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6041
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6042
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6043
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6044
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6047
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6049
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6050
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6051
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6053
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6054
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6056
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6057
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6058
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6060
ZohocorpManageengine Recoverymanager Plus Version6.0 Updatebuild6061
ZohocorpManageengine Servicedesk Plus Version14.2 Update14200
ZohocorpManageengine Servicedesk Plus Version14.2 Update14201
ZohocorpManageengine Servicedesk Plus Version14.2 Update14202
ZohocorpManageengine Servicedesk Plus Version14.2 Update14203
ZohocorpManageengine Servicedesk Plus Version14.2 Update14204
ZohocorpManageengine Servicedesk Plus Version14.3 Update14300
ZohocorpManageengine Servicedesk Plus Version14.3 Update14301
ZohocorpManageengine Servicedesk Plus Version14.3 Update14302
ZohocorpManageengine Servicedesk Plus Msp Version14.3 Update14300
ZohocorpManageengine Supportcenter Plus Version14.3 Update14300
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.36% 0.57
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.