CVE-2021-40539
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
- Affected products
- Zoho Manageengine Adselfservice Plus
- Zohocorp Manageengine Adselfservice Plus
- < 6.1
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.0% (100th percentile)
- Weakness
- CWE-706
- NVD status
- Analyzed
- Published
- 2021-09-07
CVE-2021-40539 at NVD
13 known exploits for CVE-2021-40539
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2021-40539
CVE-2021-40539
CVE-2021-40539
ADSelfService-Plus-RCE-CVE-2021-40539
CVE-2021-40539
APT-Backpack
Exploit for Use of Incorrectly-Resolved Name or Reference in Zohocorp Manageengine_Adselfservice_Plus
Exploit for Use of Incorrectly-Resolved Name or Reference in Zohocorp Manageengine_Adselfservice_Plus
Exploit for Use of Incorrectly-Resolved Name or Reference in Zohocorp Manageengine_Adselfservice_Plus
ManageEngine ADSelfService Plus Authentication Bypass / Code Execution Exploit
ManageEngine ADSelfService Plus Authentication Bypass / Code Execution
Exploit for Use of Incorrectly-Resolved Name or Reference in Zohocorp Manageengine_Adselfservice_Plus
ManageEngine ADSelfService Plus CVE-2021-40539