SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-27310

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

MEDIUM 6.5EPSS 2.27%

Does this matter?

Lower severity and a low EPSS score (2.27%). Track it; it rarely justifies an emergency change on its own.

Description

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS
2.27% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-90
Affected
zohocorp/manageengine adselfservice plus
Source
0fc0942c-577d-436f-ae8e-945763c79b02

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.