PT-2023-7423 · Zoho · Zoho Manageengine Admanager Plus+1
Published
2023-04-05
·
Updated
2023-04-12
·
CVE-2023-28342
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine ADManager Plus (affected versions not specified)
Zoho ManageEngine ADSelfService Plus versions prior to 6218
Description
The issue is related to insufficient input validation in the DomainUserSSPLogonAuth method of the Zoho ManageEngine ADManager Plus software for managing Active Directory services. This can be exploited by a remote attacker to cause a denial-of-service. The vulnerability can be triggered via the Mobile App Authentication API.
Recommendations
For Zoho ManageEngine ADManager Plus, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Zoho ManageEngine ADSelfService Plus versions prior to 6218, update to version 6218 or later to resolve the issue. As a temporary workaround, consider restricting access to the Mobile App Authentication API to minimize the risk of exploitation.
DoS
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoho Manageengine Admanager Plus
Zoho Manageengine Adselfservice Plus