Umbra Wiki cve cve/CVE-2022-28810
Back to wiki

CVE-2022-28810 — Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2022-28810

CVE-2022-28810: Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Zoho
Product ManageEngine
Date added 2023-03-07
Due date 2023-03-28
Ransomware campaign use Unknown

Description

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-28810.html; https://nvd.nist.gov/vuln/detail/CVE-2022-28810

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-28810
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog