First published: Mon May 27 2024(Updated: )
Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ADSelfService Plus | <6.4 | |
ADSelfService Plus | =6.4-6400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27310 is considered a high-severity vulnerability due to its potential for denial-of-service attacks.
CVE-2024-27310 affects all versions of Zoho ManageEngine ADSelfService Plus below 6401.
To mitigate CVE-2024-27310, upgrade to version 6401 or later of ManageEngine ADSelfService Plus.
CVE-2024-27310 allows for a denial-of-service attack due to malicious LDAP input.
Yes, a patch is included in the upgrade to version 6401 or later for CVE-2024-27310.