Junglewise Threat Intelligence

CVE-2021-40539: Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

CVE-2021-40539 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Zoho ManageEngine. Vendors: Zoho.

Executive brief

Zoho ManageEngine ADSelfService Plus is vulnerable to an authentication bypass affecting REST API URLs. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the system.

Affected products

  • Zoho Corp ManageEngine ADSelfService Plus 6113 and prior

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats