CVE-2023-35785

Severity
8.1HIGH
EPSS
0.2%
top 52.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 28

Description

Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360 UEBA 4045 and below, M365 Manager Plus 4529 and below, M365 Security Plus 4529 and below, Recovery Manager Plus 6061 and below, ServiceDesk Plus 1

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-84hj-v72f-gxc9: Zoho ManageEngine ADManager Plus through 7186 is vulnerable to 2FA bypass2023-08-28
CVEList
CVE-2023-35785: Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and be2023-08-28
CVE-2023-35785 (HIGH CVSS 8.1) | Zoho ManageEngine Active Directory | cvebase.io