PT-2023-1149 · Zoho · Zoho Manageengine Servicedesk Plus

Published

2023-01-20

·

Updated

2023-01-27

·

CVE-2023-22964

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ServiceDesk Plus MSP versions prior to 10611 Zoho ManageEngine ServiceDesk Plus versions 13.x prior to 13004
Description The issue is related to the implementation of the authentication mechanism via the LDAP protocol in the Zoho ManageEngine ServiceDesk Plus system, which is associated with deficiencies in the authentication procedure. Exploitation of this issue may allow a remote attacker to elevate their privileges. The vulnerability is specifically related to an unsafe LDAP configuration when LDAP authentication is enabled.
Recommendations For Zoho ManageEngine ServiceDesk Plus MSP versions prior to 10611, update to version 10611 or later. For Zoho ManageEngine ServiceDesk Plus versions 13.x prior to 13004, update to version 13004 or later. As a temporary workaround, consider disabling LDAP authentication until a patch is available. Restrict access to the LDAP configuration to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-00351
CVE-2023-22964

Affected Products

Zoho Manageengine Servicedesk Plus