← Volver a CVEs
CVE-2023-35854
CRITICAL9.8
Descripcion
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado6/20/2023
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
zohocorp:manageengine_adselfservice_plus
Debilidades (CWE)
CWE-306
Referencias
https://github.com/970198175/Simply-use(cve@mitre.org)
https://www.manageengine.com(cve@mitre.org)
https://github.com/970198175/Simply-use(af854a3a-2127-422b-91ae-364da2661108)
https://www.manageengine.com(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.