TROYANOSYVIRUS
Back to CVEs

CVE-2021-40539

CRITICALCISA KEV
9.8

Description

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published9/7/2021
Last Modified11/5/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorZoho
ProductManageEngine
Vulnerability NameZoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
KEV Date Added2021-11-03
Remediation Due Date2021-11-17
Ransomware UseKnown

Affected Products

zohocorp:manageengine_adselfservice_plus

Weaknesses (CWE)

CWE-706CWE-706

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.