CRITICAL
CVE-2021-40539
CVSS
9.8
KEV
Description
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
Summary dbcve.org
Zoho ManageEngine ADSelfService Plus versions 6113 and prior contain a vulnerability in the REST API authentication mechanism that allows attackers to bypass authentication and execute arbitrary code remotely, achieving full system compromise.
Mitigation
Immediately upgrade ADSelfService Plus to the patched version (6114 or later), or if immediate patching is not feasible, restrict network access to the REST API endpoints and monitor for indicators of compromise.
Weakness (CWE)
CWE-706
EPSS Score
98.96%
Probability of exploitation in next 30 days
99.9th percentile
References
http://packetstormsecurity.com/files/165085/ManageEngine-ADSelfService-Plus-Authentication-Bypass-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://www.manageengine.com
Product
https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40539
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.