CVE-2023-35854: Critical severity ZohoCorp ManageEngine ADSelfService Plus vulnerability
DISPUTED Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Zoho ManageEngine ADSelfService Plus vulnerability?
The vulnerability ID for this Zoho ManageEngine ADSelfService Plus vulnerability is CVE-2023-35854.
What is the severity level of CVE-2023-35854?
The severity level of CVE-2023-35854 is critical.
How can the authentication bypass be exploited in Zoho ManageEngine ADSelfService Plus?
The authentication bypass in Zoho ManageEngine ADSelfService Plus can be exploited to steal the domain controller session token for identity spoofing and gain the privileges of the domain controller administrator.
What is the affected software version range for this vulnerability?
The affected software version range for this vulnerability is Zoho ManageEngine ADSelfService Plus 6.1 up to 6.1-6113.
Are there any references available for CVE-2023-35854?
Yes, there are references available for CVE-2023-35854. You can find them at the following links: [reference 1](https://github.com/970198175/Simply-use) and [reference 2](https://www.manageengine.com).