CVE-2021-40539

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
zohocorpmanageengine_adselfservice_plus
𝑥
< 6.1
zohocorpmanageengine_adselfservice_plus
6.1
zohocorpmanageengine_adselfservice_plus
6.1:6100
zohocorpmanageengine_adselfservice_plus
6.1:6101
zohocorpmanageengine_adselfservice_plus
6.1:6102
zohocorpmanageengine_adselfservice_plus
6.1:6103
zohocorpmanageengine_adselfservice_plus
6.1:6104
zohocorpmanageengine_adselfservice_plus
6.1:6105
zohocorpmanageengine_adselfservice_plus
6.1:6106
zohocorpmanageengine_adselfservice_plus
6.1:6113
𝑥
= Vulnerable software versions