QID 378408

Date Published: 2023-04-20

QID 378408: Zoho ManageEngine ADSelfService Plus OTP Brute-Force Weakness Vulnerability

ManageEngine ADSelfService Plus is a secure, web-based, end-user password reset management and single sign-on solution that helps domain users to perform self-service password reset, self-service account unlock, employee self-update of personal details (e.g., mobile numbers and photos) in Microsoft Windows Active Directory.

This security advisory for ManageEngine ADSelfService Plus pertains to an OTP brute-force issue in the Password Sync Agent that could affect integrated third-party applications.

Affected Version:
Zoho ManageEngine ADSelfService Plus build 6217 and below

QID Detection Logic:
Authenticated : Checks for vulnerable version of ManageEngine ADSelfService Plus build 6217 and below

Attackers could exploit this vulnerability using specialized, highly sophisticated machines to reset passwords and take control over integrated third-party applications.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The vendor has released a patch.
    Customers are advised to visit Zoho ManageEngine ADSelfService Plus Security Advisory for updates pertaining this vulnerability.
    Vendor References

    CVEs related to QID 378408

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine ADSelfService Plus Security Advisory URL Logo www.manageengine.com/products/self-service-password/advisory/CVE-2022-36413.html