CVE-2023-22964

Severity
9.1CRITICAL
EPSS
1.0%
top 22.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20

Description

Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-p357-h73m-92rg: Zoho ManageEngine ServiceDesk Plus MSP through 13003 is vulnerable to authentication bypass due to the unsafe LDAP configuration (issue 1 of 2)2023-01-20
CVEList
CVE-2023-22964: Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled2023-01-20
CVE-2023-22964 (CRITICAL CVSS 9.1) | Zoho ManageEngine ServiceDesk Plus | cvebase.io