7.5
CWE
400
Advisory Published
Updated

CVE-2023-28342

First published: Wed Apr 05 2023(Updated: )

Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
ADSelfService Plus=4.5-4510
ADSelfService Plus=4.5-4511
ADSelfService Plus=4.5-4520
ADSelfService Plus=4.5-4522
ADSelfService Plus=4.5-4531
ADSelfService Plus=4.5-4540
ADSelfService Plus=4.5-4543
ADSelfService Plus=4.5-4544
ADSelfService Plus=4.5-4550
ADSelfService Plus=4.5-4560
ADSelfService Plus=4.5-4570
ADSelfService Plus=4.5-4571
ADSelfService Plus=4.5-4572
ADSelfService Plus=4.5-4580
ADSelfService Plus=4.5-4590
ADSelfService Plus=4.5-4591
ADSelfService Plus=4.5-4592
ADSelfService Plus=5.0-5000
ADSelfService Plus=5.0-5001
ADSelfService Plus=5.0-5002
ADSelfService Plus=5.0-5010
ADSelfService Plus=5.0-5011
ADSelfService Plus=5.0-5020
ADSelfService Plus=5.0-5021
ADSelfService Plus=5.0-5022
ADSelfService Plus=5.0-5030
ADSelfService Plus=5.0-5032
ADSelfService Plus=5.0-5040
ADSelfService Plus=5.0-5041
ADSelfService Plus=5.0.6
ADSelfService Plus=5.1-5100
ADSelfService Plus=5.1-5101
ADSelfService Plus=5.1-5102
ADSelfService Plus=5.1-5103
ADSelfService Plus=5.1-5104
ADSelfService Plus=5.1-5105
ADSelfService Plus=5.1-5106
ADSelfService Plus=5.1-5107
ADSelfService Plus=5.1-5108
ADSelfService Plus=5.1-5109
ADSelfService Plus=5.1-5110
ADSelfService Plus=5.1-5111
ADSelfService Plus=5.1-5112
ADSelfService Plus=5.1-5113
ADSelfService Plus=5.1-5114
ADSelfService Plus=5.1-5115
ADSelfService Plus=5.1-5116
ADSelfService Plus=5.2-5200
ADSelfService Plus=5.2-5201
ADSelfService Plus=5.2-5202
ADSelfService Plus=5.2-5203
ADSelfService Plus=5.2-5204
ADSelfService Plus=5.2-5205
ADSelfService Plus=5.2-5206
ADSelfService Plus=5.2-5207
ADSelfService Plus=5.3-5300
ADSelfService Plus=5.3-5301
ADSelfService Plus=5.3-5302
ADSelfService Plus=5.3-5303
ADSelfService Plus=5.3-5304
ADSelfService Plus=5.3-5305
ADSelfService Plus=5.3-5306
ADSelfService Plus=5.3-5307
ADSelfService Plus=5.3-5308
ADSelfService Plus=5.3-5309
ADSelfService Plus=5.3-5310
ADSelfService Plus=5.3-5311
ADSelfService Plus=5.3-5312
ADSelfService Plus=5.3-5313
ADSelfService Plus=5.3-5314
ADSelfService Plus=5.3-5315
ADSelfService Plus=5.3-5316
ADSelfService Plus=5.3-5317
ADSelfService Plus=5.3-5318
ADSelfService Plus=5.3-5319
ADSelfService Plus=5.3-5320
ADSelfService Plus=5.3-5321
ADSelfService Plus=5.3-5322
ADSelfService Plus=5.3-5323
ADSelfService Plus=5.3-5324
ADSelfService Plus=5.3-5325
ADSelfService Plus=5.3-5326
ADSelfService Plus=5.3-5327
ADSelfService Plus=5.3-5328
ADSelfService Plus=5.3-5329
ADSelfService Plus=5.3-5330
ADSelfService Plus=5.4-5400
ADSelfService Plus=5.5
ADSelfService Plus=5.5-5500
ADSelfService Plus=5.5-5501
ADSelfService Plus=5.5-5502
ADSelfService Plus=5.5-5503
ADSelfService Plus=5.5-5504
ADSelfService Plus=5.5-5505
ADSelfService Plus=5.5-5506
ADSelfService Plus=5.5-5507
ADSelfService Plus=5.5-5508
ADSelfService Plus=5.5-5509
ADSelfService Plus=5.5-5510
ADSelfService Plus=5.5-5511
ADSelfService Plus=5.5-5512
ADSelfService Plus=5.5-5513
ADSelfService Plus=5.5-5514
ADSelfService Plus=5.5-5515
ADSelfService Plus=5.5-5516
ADSelfService Plus=5.5-5517
ADSelfService Plus=5.5-5518
ADSelfService Plus=5.5-5519
ADSelfService Plus=5.5-5520
ADSelfService Plus=5.5-5521
ADSelfService Plus=5.6-5600
ADSelfService Plus=5.6-5601
ADSelfService Plus=5.6-5602
ADSelfService Plus=5.6-5603
ADSelfService Plus=5.6-5604
ADSelfService Plus=5.6-5605
ADSelfService Plus=5.6-5606
ADSelfService Plus=5.6-5607
ADSelfService Plus=5.7-5607
ADSelfService Plus=5.7-5700
ADSelfService Plus=5.7-5701
ADSelfService Plus=5.7-5702
ADSelfService Plus=5.7-5703
ADSelfService Plus=5.7-5704
ADSelfService Plus=5.7-5705
ADSelfService Plus=5.7-5706
ADSelfService Plus=5.7-5707
ADSelfService Plus=5.7-5708
ADSelfService Plus=5.7-5709
ADSelfService Plus=5.7-5710
ADSelfService Plus=5.8
ADSelfService Plus=5.8-5800
ADSelfService Plus=5.8-5801
ADSelfService Plus=5.8-5802
ADSelfService Plus=5.8-5803
ADSelfService Plus=5.8-5804
ADSelfService Plus=5.8-5805
ADSelfService Plus=5.8-5806
ADSelfService Plus=5.8-5807
ADSelfService Plus=5.8-5808
ADSelfService Plus=5.8-5809
ADSelfService Plus=5.8-5810
ADSelfService Plus=5.8-5811
ADSelfService Plus=5.8-5812
ADSelfService Plus=5.8-5813
ADSelfService Plus=5.8-5814
ADSelfService Plus=5.8-5815
ADSelfService Plus=5.8-5816
ADSelfService Plus=6.0
ADSelfService Plus=6.0-6000
ADSelfService Plus=6.0-6001
ADSelfService Plus=6.0-6002
ADSelfService Plus=6.0-6003
ADSelfService Plus=6.0-6004
ADSelfService Plus=6.0-6005
ADSelfService Plus=6.0-6006
ADSelfService Plus=6.0-6007
ADSelfService Plus=6.0-6008
ADSelfService Plus=6.0-6009
ADSelfService Plus=6.0-6012
ADSelfService Plus=6.0-6013
ADSelfService Plus=6.1
ADSelfService Plus=6.1-6100
ADSelfService Plus=6.1-6101
ADSelfService Plus=6.1-6102
ADSelfService Plus=6.1-6103
ADSelfService Plus=6.1-6104
ADSelfService Plus=6.1-6105
ADSelfService Plus=6.1-6106
ADSelfService Plus=6.1-6107
ADSelfService Plus=6.1-6108
ADSelfService Plus=6.1-6109
ADSelfService Plus=6.1-6110
ADSelfService Plus=6.1-6111
ADSelfService Plus=6.1-6112
ADSelfService Plus=6.1-6113
ADSelfService Plus=6.1-6114
ADSelfService Plus=6.1-6115
ADSelfService Plus=6.1-6116
ADSelfService Plus=6.1-6117
ADSelfService Plus=6.1-6118
ADSelfService Plus=6.1-6119
ADSelfService Plus=6.1-6120
ADSelfService Plus=6.1-6121
ADSelfService Plus=6.1-6122
ADSelfService Plus=6.1-6123
ADSelfService Plus=6.2-6200
ADSelfService Plus=6.2-6201
ADSelfService Plus=6.2-6202
ADSelfService Plus=6.2-6203
ADSelfService Plus=6.2-6204
ADSelfService Plus=6.2-6205
ADSelfService Plus=6.2-6206
ADSelfService Plus=6.2-6207
ADSelfService Plus=6.2-6208
ADSelfService Plus=6.2-6209
ADSelfService Plus=6.2-6210
ADSelfService Plus=6.2-6211
ADSelfService Plus=6.2-6212
ADSelfService Plus=6.2-6213
ADSelfService Plus=6.2-6214
ADSelfService Plus=6.2-6215
ADSelfService Plus=6.2-6216
ADSelfService Plus=6.2-6217

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2023-28342?

    CVE-2023-28342 is classified as a high severity vulnerability due to its potential to allow Denial-of-Service attacks.

  • How do I fix CVE-2023-28342?

    To fix CVE-2023-28342, it is recommended to upgrade to the latest version of Zoho ManageEngine ADSelfService Plus.

  • Which versions of ManageEngine ADSelfService Plus are affected by CVE-2023-28342?

    Versions before 6218, including 4.5-4510, 4.5-4511, and various 5.x and 6.x versions, are affected by CVE-2023-28342.

  • What kind of attack can be executed using CVE-2023-28342?

    CVE-2023-28342 allows an attacker to conduct a Denial-of-Service attack through the Mobile App Authentication API.

  • Is there a workaround for CVE-2023-28342 before applying the fix?

    Currently, the best course of action is to apply the security patch or upgrade ManageEngine ADSelfService Plus to mitigate CVE-2023-28342.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203