CVE-2021-37424

Severity
9.8CRITICAL
EPSS
13.6%
top 5.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateMay 24

Description

ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fcp4-47q7-p53r: ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover2022-05-24
CVEList
CVE-2021-37424: ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover2021-09-21
CVE-2021-37424 (CRITICAL CVSS 9.8) | ManageEngine ADSelfService Plus bef | cvebase.io