ZDI-CAN-21010: ZDI-23-1488: ManageEngine ADManager Plus installServiceWithCredentials Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of ManageEngine ADManager Plus. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2023-38743.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21010?
The CVSS rating assigned to ZDI-CAN-21010 is 7.2, indicating a high severity vulnerability.
How do I fix ZDI-CAN-21010?
To fix ZDI-CAN-21010, ensure that you update to the latest version of ManageEngine ADManager Plus that addresses this vulnerability.
What type of attack does ZDI-CAN-21010 involve?
ZDI-CAN-21010 involves remote code execution attacks that require authentication to exploit.
What impact does ZDI-CAN-21010 have?
ZDI-CAN-21010 allows remote attackers to execute arbitrary code on affected installations of ManageEngine ADManager Plus.
Is authentication needed to exploit ZDI-CAN-21010?
Yes, authentication is required to exploit the vulnerability identified as ZDI-CAN-21010.