CVE-2023-35785

Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360 UEBA 4045 and below, M365 Manager Plus 4529 and below, M365 Security Plus 4529 and below, Recovery Manager Plus 6061 and below, ServiceDesk Plus 14204 and below and 143xx 14302 and below, ServiceDesk Plus MSP 14300 and below, SharePoint Manager Plus 4402 and below, and Support Center Plus 14300 and below are vulnerable to 2FA bypass via a few TOTP authenticators. Note: A valid pair of username and password is required to leverage this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
zohocorpmanageengine_ad360
𝑥
< 4.3
zohocorpmanageengine_ad360
4.3:4300
zohocorpmanageengine_ad360
4.3:4302
zohocorpmanageengine_ad360
4.3:4303
zohocorpmanageengine_ad360
4.3:4304
zohocorpmanageengine_ad360
4.3:4305
zohocorpmanageengine_ad360
4.3:4306
zohocorpmanageengine_ad360
4.3:4308
zohocorpmanageengine_ad360
4.3:4309
zohocorpmanageengine_ad360
4.3:4310
zohocorpmanageengine_ad360
4.3:4312
zohocorpmanageengine_ad360
4.3:4313
zohocorpmanageengine_ad360
4.3:4314
zohocorpmanageengine_ad360
4.3:4315
zohocorpmanageengine_adaudit_plus
𝑥
< 7.2
zohocorpmanageengine_adaudit_plus
7.2:7200
zohocorpmanageengine_adaudit_plus
7.2:7201
zohocorpmanageengine_adaudit_plus
7.2:7202
zohocorpmanageengine_admanager_plus
𝑥
< 7.2
zohocorpmanageengine_admanager_plus
7.2:7201
zohocorpmanageengine_assetexplorer
𝑥
< 6.9
zohocorpmanageengine_assetexplorer
6.9
zohocorpmanageengine_assetexplorer
6.9:6900
zohocorpmanageengine_assetexplorer
6.9:6901
zohocorpmanageengine_assetexplorer
6.9:6902
zohocorpmanageengine_assetexplorer
6.9:6903
zohocorpmanageengine_assetexplorer
6.9:6904
zohocorpmanageengine_assetexplorer
6.9:6905
zohocorpmanageengine_assetexplorer
6.9:6906
zohocorpmanageengine_assetexplorer
6.9:6907
zohocorpmanageengine_assetexplorer
6.9:6908
zohocorpmanageengine_assetexplorer
6.9:6909
zohocorpmanageengine_assetexplorer
6.9:6950
zohocorpmanageengine_assetexplorer
6.9:6951
zohocorpmanageengine_assetexplorer
6.9:6952
zohocorpmanageengine_assetexplorer
6.9:6953
zohocorpmanageengine_assetexplorer
6.9:6954
zohocorpmanageengine_assetexplorer
6.9:6955
zohocorpmanageengine_assetexplorer
6.9:6956
zohocorpmanageengine_assetexplorer
6.9:6957
zohocorpmanageengine_assetexplorer
6.9:6970
zohocorpmanageengine_assetexplorer
6.9:6971
zohocorpmanageengine_assetexplorer
6.9:6972
zohocorpmanageengine_assetexplorer
6.9:6973
zohocorpmanageengine_assetexplorer
6.9:6974
zohocorpmanageengine_assetexplorer
6.9:6975
zohocorpmanageengine_assetexplorer
6.9:6976
zohocorpmanageengine_assetexplorer
6.9:6977
zohocorpmanageengine_assetexplorer
6.9:6978
zohocorpmanageengine_assetexplorer
6.9:6979
zohocorpmanageengine_assetexplorer
6.9:6980
zohocorpmanageengine_assetexplorer
6.9:6981
zohocorpmanageengine_assetexplorer
6.9:6982
zohocorpmanageengine_assetexplorer
6.9:6983
zohocorpmanageengine_assetexplorer
6.9:6984
zohocorpmanageengine_assetexplorer
6.9:6985
zohocorpmanageengine_assetexplorer
6.9:6986
zohocorpmanageengine_assetexplorer
6.9:6987
zohocorpmanageengine_assetexplorer
6.9:6988
zohocorpmanageengine_assetexplorer
6.9:6989
zohocorpmanageengine_assetexplorer
6.9:6990
zohocorpmanageengine_assetexplorer
6.9:6991
zohocorpmanageengine_assetexplorer
6.9:6992
zohocorpmanageengine_assetexplorer
6.9:6993
zohocorpmanageengine_assetexplorer
7.0:7000
zohocorpmanageengine_assetexplorer
7.0:7001
zohocorpmanageengine_cloud_security_plus
𝑥
< 4.1
zohocorpmanageengine_cloud_security_plus
4.1:4100
zohocorpmanageengine_cloud_security_plus
4.1:4101
zohocorpmanageengine_cloud_security_plus
4.1:4102
zohocorpmanageengine_cloud_security_plus
4.1:4103
zohocorpmanageengine_cloud_security_plus
4.1:4104
zohocorpmanageengine_cloud_security_plus
4.1:4105
zohocorpmanageengine_cloud_security_plus
4.1:4106
zohocorpmanageengine_cloud_security_plus
4.1:4107
zohocorpmanageengine_cloud_security_plus
4.1:4108
zohocorpmanageengine_cloud_security_plus
4.1:4109
zohocorpmanageengine_cloud_security_plus
4.1:4110
zohocorpmanageengine_cloud_security_plus
4.1:4111
zohocorpmanageengine_cloud_security_plus
4.1:4112
zohocorpmanageengine_cloud_security_plus
4.1:4113
zohocorpmanageengine_cloud_security_plus
4.1:4115
zohocorpmanageengine_cloud_security_plus
4.1:4116
zohocorpmanageengine_cloud_security_plus
4.1:4117
zohocorpmanageengine_cloud_security_plus
4.1:4118
zohocorpmanageengine_cloud_security_plus
4.1:4119
zohocorpmanageengine_cloud_security_plus
4.1:4120
zohocorpmanageengine_cloud_security_plus
4.1:4121
zohocorpmanageengine_cloud_security_plus
4.1:4122
zohocorpmanageengine_cloud_security_plus
4.1:4130
zohocorpmanageengine_cloud_security_plus
4.1:4131
zohocorpmanageengine_cloud_security_plus
4.1:4140
zohocorpmanageengine_cloud_security_plus
4.1:4141
zohocorpmanageengine_cloud_security_plus
4.1:4150
zohocorpmanageengine_cloud_security_plus
4.1:4160
zohocorpmanageengine_cloud_security_plus
4.1:4161
zohocorpmanageengine_datasecurity_plus
𝑥
< 6.1
zohocorpmanageengine_datasecurity_plus
6.1:6100
zohocorpmanageengine_datasecurity_plus
6.1:6101
zohocorpmanageengine_datasecurity_plus
6.1:6110
zohocorpmanageengine_eventlog_analyzer
𝑥
< 12.3.0
zohocorpmanageengine_eventlog_analyzer
12.3.0:12300
zohocorpmanageengine_eventlog_analyzer
12.3.0:12301
zohocorpmanageengine_exchange_reporter_plus
𝑥
< 5.7
zohocorpmanageengine_exchange_reporter_plus
5.7:5700
zohocorpmanageengine_exchange_reporter_plus
5.7:5701
zohocorpmanageengine_exchange_reporter_plus
5.7:5702
zohocorpmanageengine_exchange_reporter_plus
5.7:5703
zohocorpmanageengine_exchange_reporter_plus
5.7:5704
zohocorpmanageengine_exchange_reporter_plus
5.7:5705
zohocorpmanageengine_exchange_reporter_plus
5.7:5706
zohocorpmanageengine_exchange_reporter_plus
5.7:5707
zohocorpmanageengine_exchange_reporter_plus
5.7:5708
zohocorpmanageengine_exchange_reporter_plus
5.7:5709
zohocorpmanageengine_log360
𝑥
< 5.3
zohocorpmanageengine_log360
5.3:build5300
zohocorpmanageengine_log360
5.3:build5301
zohocorpmanageengine_log360
5.3:build5302
zohocorpmanageengine_log360
5.3:build5305
zohocorpmanageengine_log360
5.3:build5310
zohocorpmanageengine_log360
5.3:build5311
zohocorpmanageengine_log360
5.3:build5315
zohocorpmanageengine_log360_ueba
4.0:build4010
zohocorpmanageengine_log360_ueba
4.0:build4011
zohocorpmanageengine_log360_ueba
4.0:build4015
zohocorpmanageengine_log360_ueba
4.0:build4016
zohocorpmanageengine_log360_ueba
4.0:build4020
zohocorpmanageengine_log360_ueba
4.0:build4021
zohocorpmanageengine_log360_ueba
4.0:build4023
zohocorpmanageengine_log360_ueba
4.0:build4024
zohocorpmanageengine_log360_ueba
4.0:build4025
zohocorpmanageengine_log360_ueba
4.0:build4026
zohocorpmanageengine_log360_ueba
4.0:build4027
zohocorpmanageengine_log360_ueba
4.0:build4028
zohocorpmanageengine_log360_ueba
4.0:build4030
zohocorpmanageengine_log360_ueba
4.0:build4031
zohocorpmanageengine_log360_ueba
4.0:build4034
zohocorpmanageengine_log360_ueba
4.0:build4035
zohocorpmanageengine_log360_ueba
4.0:build4036
zohocorpmanageengine_log360_ueba
4.0:build4040
zohocorpmanageengine_log360_ueba
4.0:build4043
zohocorpmanageengine_log360_ueba
4.0:build4045
zohocorpmanageengine_m365_manager_plus
𝑥
< 4.5
zohocorpmanageengine_m365_manager_plus
4.5:build4500
zohocorpmanageengine_m365_manager_plus
4.5:build4502
zohocorpmanageengine_m365_manager_plus
4.5:build4503
zohocorpmanageengine_m365_manager_plus
4.5:build4504
zohocorpmanageengine_m365_manager_plus
4.5:build4505
zohocorpmanageengine_m365_manager_plus
4.5:build4507
zohocorpmanageengine_m365_manager_plus
4.5:build4508
zohocorpmanageengine_m365_manager_plus
4.5:build4509
zohocorpmanageengine_m365_manager_plus
4.5:build4510
zohocorpmanageengine_m365_manager_plus
4.5:build4511
zohocorpmanageengine_m365_manager_plus
4.5:build4512
zohocorpmanageengine_m365_manager_plus
4.5:build4513
zohocorpmanageengine_m365_manager_plus
4.5:build4514
zohocorpmanageengine_m365_manager_plus
4.5:build4516
zohocorpmanageengine_m365_manager_plus
4.5:build4517
zohocorpmanageengine_m365_manager_plus
4.5:build4518
zohocorpmanageengine_m365_manager_plus
4.5:build4519
zohocorpmanageengine_m365_manager_plus
4.5:build4520
zohocorpmanageengine_m365_manager_plus
4.5:build4523
zohocorpmanageengine_m365_manager_plus
4.5:build4525
zohocorpmanageengine_m365_manager_plus
4.5:build4527
zohocorpmanageengine_m365_manager_plus
4.5:build4528
zohocorpmanageengine_m365_manager_plus
4.5:build4529
zohocorpmanageengine_m365_security_plus
𝑥
< 4.5
zohocorpmanageengine_m365_security_plus
4.5:4500
zohocorpmanageengine_m365_security_plus
4.5:4502
zohocorpmanageengine_m365_security_plus
4.5:4503
zohocorpmanageengine_m365_security_plus
4.5:4504
zohocorpmanageengine_m365_security_plus
4.5:4505
zohocorpmanageengine_m365_security_plus
4.5:4507
zohocorpmanageengine_m365_security_plus
4.5:4508
zohocorpmanageengine_m365_security_plus
4.5:4509
zohocorpmanageengine_m365_security_plus
4.5:4510
zohocorpmanageengine_m365_security_plus
4.5:4511
zohocorpmanageengine_m365_security_plus
4.5:4512
zohocorpmanageengine_m365_security_plus
4.5:4513
zohocorpmanageengine_m365_security_plus
4.5:4514
zohocorpmanageengine_m365_security_plus
4.5:4516
zohocorpmanageengine_m365_security_plus
4.5:4517
zohocorpmanageengine_m365_security_plus
4.5:4518
zohocorpmanageengine_m365_security_plus
4.5:4519
zohocorpmanageengine_m365_security_plus
4.5:4520
zohocorpmanageengine_m365_security_plus
4.5:4523
zohocorpmanageengine_m365_security_plus
4.5:4525
zohocorpmanageengine_m365_security_plus
4.5:4527
zohocorpmanageengine_m365_security_plus
4.5:4528
zohocorpmanageengine_m365_security_plus
4.5:4529
zohocorpmanageengine_recoverymanager_plus
𝑥
< 6.0
zohocorpmanageengine_recoverymanager_plus
6.0:build6001
zohocorpmanageengine_recoverymanager_plus
6.0:build6003
zohocorpmanageengine_recoverymanager_plus
6.0:build6005
zohocorpmanageengine_recoverymanager_plus
6.0:build6011
zohocorpmanageengine_recoverymanager_plus
6.0:build6016
zohocorpmanageengine_recoverymanager_plus
6.0:build6017
zohocorpmanageengine_recoverymanager_plus
6.0:build6020
zohocorpmanageengine_recoverymanager_plus
6.0:build6025
zohocorpmanageengine_recoverymanager_plus
6.0:build6026
zohocorpmanageengine_recoverymanager_plus
6.0:build6030
zohocorpmanageengine_recoverymanager_plus
6.0:build6031
zohocorpmanageengine_recoverymanager_plus
6.0:build6032
zohocorpmanageengine_recoverymanager_plus
6.0:build6041
zohocorpmanageengine_recoverymanager_plus
6.0:build6042
zohocorpmanageengine_recoverymanager_plus
6.0:build6043
zohocorpmanageengine_recoverymanager_plus
6.0:build6044
zohocorpmanageengine_recoverymanager_plus
6.0:build6047
zohocorpmanageengine_recoverymanager_plus
6.0:build6049
zohocorpmanageengine_recoverymanager_plus
6.0:build6050
zohocorpmanageengine_recoverymanager_plus
6.0:build6051
zohocorpmanageengine_recoverymanager_plus
6.0:build6053
zohocorpmanageengine_recoverymanager_plus
6.0:build6054
zohocorpmanageengine_recoverymanager_plus
6.0:build6056
zohocorpmanageengine_recoverymanager_plus
6.0:build6057
zohocorpmanageengine_recoverymanager_plus
6.0:build6058
zohocorpmanageengine_recoverymanager_plus
6.0:build6060
zohocorpmanageengine_recoverymanager_plus
6.0:build6061
zohocorpmanageengine_servicedesk_plus
𝑥
< 14.2
zohocorpmanageengine_servicedesk_plus
14.2:14200
zohocorpmanageengine_servicedesk_plus
14.2:14201
zohocorpmanageengine_servicedesk_plus
14.2:14202
zohocorpmanageengine_servicedesk_plus
14.2:14203
zohocorpmanageengine_servicedesk_plus
14.2:14204
zohocorpmanageengine_servicedesk_plus
14.3:14300
zohocorpmanageengine_servicedesk_plus
14.3:14301
zohocorpmanageengine_servicedesk_plus
14.3:14302
zohocorpmanageengine_servicedesk_plus_msp
𝑥
< 14.3
zohocorpmanageengine_servicedesk_plus_msp
14.3:14300
zohocorpmanageengine_sharepoint_manager_plus
𝑥
< 4.4
zohocorpmanageengine_sharepoint_manager_plus
4.4:4400
zohocorpmanageengine_sharepoint_manager_plus
4.4:4401
zohocorpmanageengine_sharepoint_manager_plus
4.4:4402
zohocorpmanageengine_supportcenter_plus
𝑥
< 14.3
zohocorpmanageengine_supportcenter_plus
14.3:14300
𝑥
= Vulnerable software versions