SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-40539

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

KEVCRITICAL 9.8EPSS 99.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
98.96% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 17 November 2021 · used in ransomware campaigns
Weakness
CWE-706
Affected
zohocorp/manageengine adselfservice plus
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-40539

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.