Improper Authentication in Zoho ManageEngine ServiceDesk Plus MSP - #VU71170

 

Improper Authentication in Zoho ManageEngine ServiceDesk Plus MSP - #VU71170

Published: January 13, 2023


Vulnerability identifier: #VU71170
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in Active Directory/LDAP component. A remote attacker can bypass authentication process and gain unauthorized access to the application.


Affected software

Zoho ManageEngine ServiceDesk Plus MSP

Remediation

Install updates from vendor's website.

Zoho ManageEngine ServiceDesk Plus MSP - update to 13004

External References

Related Security Bulletins