CVE-2021-40539KEV · OVERDUE

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Critical · published September 7, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 99.9th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
99%
Percentile
99.9
In the wild
Confirmed
What it is

🚨 A simple API call is all it takes to bypass authentication in Zoho ManageEngine ADSelfService Plus! 🔥 Think of it like a restaurant where a customer can just walk in and sit down at a VIP table without any checks — that’s how easy it is for an attacker to gain unauthorized access here! An attacker exploiting this vulnerability could potentially execute arbitrary code on your server, leading to a catastrophic breach of sensitive data and total system compromise. Imagine someone crashing your party and taking control — that's not just a bad night, it's a security disaster!

Put simply

Think of it like a restaurant where a customer can just walk in and sit down at a VIP table without any checks — that’s how easy it is for an attacker to gain unauthorized access here! CVE-2021-40539 is a REST API authentication bypass vulnerability that allows unauthenticated users to execute remote code, putting your system at risk. Versions 6113 and earlier of ADSelfService Plus are affected, making it an urgent risk if still in use.

What to do

An attacker exploiting this vulnerability could potentially execute arbitrary code on your server, leading to a catastrophic breach of sensitive data and total system compromise. Imagine someone crashing your party and taking control — that's not just a bad night, it's a security disaster! Immediately upgrade your Zoho ManageEngine ADSelfService Plus to version 6114 or later. Additionally, review your API access controls and ensure that only authorized requests are processed. Don’t let this vulnerability linger! You’ve got this! Follow these steps, and your systems will be back on the road to safety in no time! 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.98960 · 99.9th percentile
Published
2021-09-07T16:06Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 07 SEP 16:06Z
    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution
    cvelistv5