CVE-2021-37424

ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
zohocorpmanageengine_admanager_plus
𝑥
< 6.1
zohocorpmanageengine_admanager_plus
6.1
zohocorpmanageengine_admanager_plus
6.1:6100
zohocorpmanageengine_admanager_plus
6.1:6101
zohocorpmanageengine_admanager_plus
6.1:6102
zohocorpmanageengine_admanager_plus
6.1:6103
zohocorpmanageengine_admanager_plus
6.1:6104
zohocorpmanageengine_admanager_plus
6.1:6105
zohocorpmanageengine_admanager_plus
6.1:6106
zohocorpmanageengine_admanager_plus
6.1:6107
zohocorpmanageengine_admanager_plus
6.1:6108
zohocorpmanageengine_admanager_plus
6.1:6109
zohocorpmanageengine_admanager_plus
6.1:6110
zohocorpmanageengine_admanager_plus
6.1:6111
𝑥
= Vulnerable software versions