CRITICAL

CVE-2021-40539

Zohocorp Manageengine Adselfservice Plus 2021-09-07 CVSS v3.1
CVSS
9.8
KEV

Description

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

Summary dbcve.org

Zoho ManageEngine ADSelfService Plus versions 6113 and prior contain a vulnerability in the REST API authentication mechanism that allows attackers to bypass authentication and execute arbitrary code remotely, achieving full system compromise.

Mitigation

Immediately upgrade ADSelfService Plus to the patched version (6114 or later), or if immediate patching is not feasible, restrict network access to the REST API endpoints and monitor for indicators of compromise.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-706

EPSS Score

98.96%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE