SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-3272

accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via…

MEDIUM 4.3EPSS 4.02%

Does this matter?

Lower severity and a low EPSS score (4.02%). Track it; it rarely justifies an emergency change on its own.

Description

accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
4.02% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
zohocorp/manageengine adselfservice plus
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.