HIGH
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API
Published Apr 5, 2023
7.5
HIGHCVSS 3.1
EPSS 78.34%
Description
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
Affected products
No data.
OR
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0.6
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.2
- 5.2
- 5.2
- 5.2
- 5.2
- 5.2
- 5.2
- 5.2
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.3
- 5.4
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.6
- 5.6
- 5.6
- 5.6
- 5.6
- 5.6
- 5.6
- 5.6
- 5.7
- 5.7
- 5.7
- 5.7
- 5.7
- 5.7
- 5.7
- 5.7
- 5.7
- 5.7
- 5.7
- 5.7
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 5.8
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-32040 Advisory
- https://manageengine.com Product
- https://www.manageengine.com/products/self-service-password/advisory/CVE-2023-28342.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-32040 | Advisory | |
| https://manageengine.com | Product | |
| https://www.manageengine.com/products/self-service-password/advisory/CVE-2023-28342.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 5, 2023
Updated Feb 13, 2025
Reserved Mar 14, 2023
Link CVE-2023-28342
CISA Vulnrichment
Updated Feb 13, 2025
ENISA EUVD
EUVD-2023-32040 Assigner mitre
Published Apr 5, 2023
Updated Feb 13, 2025
Exploited since n/a
Link EUVD-2023-32040