Improper Authentication in Zoho ManageEngine ServiceDesk Plus MSP - #VU71170
Published: January 13, 2023
Vulnerability identifier: #VU71170
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in Active Directory/LDAP component. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Affected software
Zoho ManageEngine ServiceDesk Plus MSP
Remediation
Install updates from vendor's website.
Zoho ManageEngine ServiceDesk Plus MSP - update to 13004