PT-2023-9278 · Zoho · Zoho Manageengine Adselfservice Plus

Nhien Pham

·

Publicado

2023-12-27

·

Atualizado

2024-11-27

·

CVE-2024-27310

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ADSelfService Plus versions below 6401
Description The issue is related to an uncontrolled resource consumption in the password reset software, which can be exploited by a remote attacker to cause a denial of service. The vulnerability is caused by malicious LDAP input, allowing an attacker to disrupt the service.
Recommendations For Zoho ManageEngine ADSelfService Plus versions below 6401, consider restricting access to the LDAP functionality until a patch is available. As a temporary workaround, avoid using the vulnerable LDAP query functionality in the affected software until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-05903
CVE-2024-27310

Produtos afetados

Zoho Manageengine Adselfservice Plus