CVE-2021-40539
CVE Published | 2021-09-07 |
---|---|
Related CWE(s) | CWE-706: Use of Incorrectly-Resolved Name or Reference |
Related Vendor(s) | zohocorp |
Related Product(s) | manageengine_adselfservice_plus |
Exploitation Reported (CISA KEV) | 2021-11-03 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph
Threat Reports Related to CVE-2021-40539
Report
People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection
This advisory from the US National Security Agency, CISA and various other agencies outlines tactics, techniques and procedures used by Volt ...