PT-2023-7423 · Zoho · Zoho Manageengine Admanager Plus+1

Published

2023-04-05

·

Updated

2023-04-12

·

CVE-2023-28342

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ADManager Plus (affected versions not specified) Zoho ManageEngine ADSelfService Plus versions prior to 6218
Description The issue is related to insufficient input validation in the DomainUserSSPLogonAuth method of the Zoho ManageEngine ADManager Plus software for managing Active Directory services. This can be exploited by a remote attacker to cause a denial-of-service. The vulnerability can be triggered via the Mobile App Authentication API.
Recommendations For Zoho ManageEngine ADManager Plus, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Zoho ManageEngine ADSelfService Plus versions prior to 6218, update to version 6218 or later to resolve the issue. As a temporary workaround, consider restricting access to the Mobile App Authentication API to minimize the risk of exploitation.

DoS

Resource Exhaustion

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-08460
CVE-2023-28342
ZDI-23-437

Affected Products

Zoho Manageengine Admanager Plus
Zoho Manageengine Adselfservice Plus