CVE-2021-33055
Severity
9.8CRITICAL
EPSS
21.8%
top 4.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30
Latest updateMay 24
Description
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages1 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-7cpr-q2xm-pm67: Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions↗2022-05-24
CVEList▶
CVE-2021-33055: Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions↗2021-08-30