CVE-2021-40539 — Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
CVE-2021-40539: Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Zoho |
| Product | ManageEngine |
| Date added | 2021-11-03 |
| Due date | 2021-11-17 |
| Ransomware campaign use | Known |
Description
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-40539
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-40539
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog