PT-2023-9278 · Zoho · Zoho Manageengine Adselfservice Plus

Nhien Pham

·

Published

2023-12-27

·

Updated

2024-11-27

·

CVE-2024-27310

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ADSelfService Plus versions below 6401
Description The issue is related to an uncontrolled resource consumption in the password reset software, which can be exploited by a remote attacker to cause a denial of service. The vulnerability is caused by malicious LDAP input, allowing an attacker to disrupt the service.
Recommendations For Zoho ManageEngine ADSelfService Plus versions below 6401, consider restricting access to the LDAP functionality until a patch is available. As a temporary workaround, avoid using the vulnerable LDAP query functionality in the affected software until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-05903
CVE-2024-27310

Affected Products

Zoho Manageengine Adselfservice Plus