5.4

CVE-2023-41904

Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7200
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7201
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7202
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.99% 0.78
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-41904.html
Vendor Advisory