// For flags

CVE-2022-36413

 

Severity Score

9.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-07-23 CVE Reserved
  • 2023-03-23 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-10-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-307: Improper Restriction of Excessive Authentication Attempts
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
< 6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version " < 6.2"
-
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6200
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6201
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6202
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6203
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6204
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6205
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6206
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6207
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6208
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6209
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6210
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6211
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6212
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6213
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6214
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6215
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6216
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Adselfservice Plus
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus"
6.2
Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.2"
6217
Affected