CVE-2022-28810
18.04.2022, 13:15
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_adselfservice_plus | 𝑥 < 6.1 |
zohocorp | manageengine_adselfservice_plus | 6.1 |
zohocorp | manageengine_adselfservice_plus | 6.1:6100 |
zohocorp | manageengine_adselfservice_plus | 6.1:6101 |
zohocorp | manageengine_adselfservice_plus | 6.1:6102 |
zohocorp | manageengine_adselfservice_plus | 6.1:6103 |
zohocorp | manageengine_adselfservice_plus | 6.1:6104 |
zohocorp | manageengine_adselfservice_plus | 6.1:6105 |
zohocorp | manageengine_adselfservice_plus | 6.1:6106 |
zohocorp | manageengine_adselfservice_plus | 6.1:6107 |
zohocorp | manageengine_adselfservice_plus | 6.1:6108 |
zohocorp | manageengine_adselfservice_plus | 6.1:6109 |
zohocorp | manageengine_adselfservice_plus | 6.1:6110 |
zohocorp | manageengine_adselfservice_plus | 6.1:6111 |
zohocorp | manageengine_adselfservice_plus | 6.1:6112 |
zohocorp | manageengine_adselfservice_plus | 6.1:6113 |
zohocorp | manageengine_adselfservice_plus | 6.1:6114 |
zohocorp | manageengine_adselfservice_plus | 6.1:6115 |
zohocorp | manageengine_adselfservice_plus | 6.1:6116 |
zohocorp | manageengine_adselfservice_plus | 6.1:6117 |
zohocorp | manageengine_adselfservice_plus | 6.1:6118 |
zohocorp | manageengine_adselfservice_plus | 6.1:6119 |
zohocorp | manageengine_adselfservice_plus | 6.1:6120 |
zohocorp | manageengine_adselfservice_plus | 6.1:6121 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
- CWE-798 - Use of Hard-coded CredentialsThe software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
References