QID 378838

Date Published: 2024-03-14

QID 378838: Zoho ManageEngine TFA bypass Vulnerability

ManageEngine offers enterprise IT management software for your service management, operations management, Active Directory and security needs.

Multiple TFA bypass vulnerabilities (CVE-2023-35785) were discovered in AD Audit Plus, ADManager Plus, Asset Explorer, Data Security Plus, Log360, ServiceDesk Plus, ServiceDesk Plus MSP and Support Center Plus.

Affected Versions:
AD Audit Plus - 7202 and below
ADManager Plus - 7200 and below
Asset Explorer - 6993 and below
Data Security Plus - 6110 and below
Log360 - 5315 and below
ServiceDesk Plus - 14302 and below
ServiceDesk Plus MSP - 14300 and below
Support Center Plus - 14300 and below
QID Detection Logic:
. Authenticated : This QID checks the product.conf file to check if latest build is installed

These vulnerabilities can allow to gain access to the application and get users sensitive information.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released patch. Customers are advised to refer to Zoho ManageEngine Advisory for more details.
    Vendor References

    CVEs related to QID 378838

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine Security Advisory URL Logo www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html