CVE-2024-27310: DOS Vulnerability
Published May 27, 2024
·Updated
Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
Affected Software
2 affected components
ZohoCorp ManageEngine ADSelfService Plus<6.4
ZohoCorp ManageEngine ADSelfService Plus=6.4-6400
Event History
May 27, 2024
CVE Published
via MITRE·05:26 PM
Data Sourced
via MITRE·05:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-27310?
CVE-2024-27310 is considered a high-severity vulnerability due to its potential for denial-of-service attacks.
2
What versions are affected by CVE-2024-27310?
CVE-2024-27310 affects all versions of Zoho ManageEngine ADSelfService Plus below 6401.
3
How do I fix CVE-2024-27310?
To mitigate CVE-2024-27310, upgrade to version 6401 or later of ManageEngine ADSelfService Plus.
4
What type of attack does CVE-2024-27310 allow?
CVE-2024-27310 allows for a denial-of-service attack due to malicious LDAP input.
5
Is there a patch available for CVE-2024-27310?
Yes, a patch is included in the upgrade to version 6401 or later for CVE-2024-27310.