MEDIUM

CVE-2022-28810

Zohocorp Manageengine Adselfservice Plus 2022-04-18 CVSS v3.1
CVSS
6.8
KEV

Description

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

Summary dbcve.org

Zoho ManageEngine ADSelfService Plus before build 6122 contains a command injection vulnerability allowing remote authenticated administrators to execute arbitrary OS commands as SYSTEM via the policy custom script feature. The presence of default administrator passwords enables unauthenticated or minimally-authenticated attackers to exploit this. Additionally, an unsanitized password field allows command injection by partially authenticated attackers.

Mitigation

Upgrade to ADSelfService Plus build 6122 or later immediately. Change all default administrator passwords and enforce strong password policies. Restrict administrative access to trusted networks and implement network segmentation.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-78 OS Command Injection
CWE-798 Hard-coded Credentials

EPSS Score

70.97%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE