CVE-2023-35854
 
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-06-19 CVE Reserved
- 2023-06-20 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/970198175/Simply-use | Third Party Advisory | |
https://www.manageengine.com | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | < 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version " < 6.1" | - |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | - |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6100 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6101 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6102 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6103 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6104 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6105 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6106 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6107 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6108 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6109 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6110 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6111 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Adselfservice Plus Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" | 6.1 Search vendor "Zohocorp" for product "Manageengine Adselfservice Plus" and version "6.1" | 6112 |
Affected
|