2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2023-22964" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2023-01-20T17:15:11.003" ,
"lastModified" : "2023-01-27T15:04:24.470" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled."
2024-09-15 02:03:16 +00:00
} ,
{
"lang" : "es" ,
"value" : "Zoho ManageEngine ServiceDesk Plus MSP anterior a 10611 y 13x anterior a 13004 es vulnerable a la omisi\u00f3n de autenticaci\u00f3n cuando la autenticaci\u00f3n LDAP est\u00e1 habilitada."
2023-04-24 12:24:31 +02:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 9.1 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.2
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-287"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10600:*:*:*:*:*:*" ,
"matchCriteriaId" : "877000C8-0405-481D-95CC-72B783457401"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10601:*:*:*:*:*:*" ,
"matchCriteriaId" : "1DC5243C-C10E-46A1-A71E-7E736FC651E2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10602:*:*:*:*:*:*" ,
"matchCriteriaId" : "C17D5800-8A5A-44BE-ACE3-6FB21631551C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10603:*:*:*:*:*:*" ,
"matchCriteriaId" : "D27B7FA3-95C7-469F-BAB8-3CAE35AE7CD1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10604:*:*:*:*:*:*" ,
"matchCriteriaId" : "C1671DFA-9DAA-41E5-9528-50F63D32FBF1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10605:*:*:*:*:*:*" ,
"matchCriteriaId" : "9F539D31-62C3-4129-8B56-8CDCD8F8E0A8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10606:*:*:*:*:*:*" ,
"matchCriteriaId" : "B3BAC4E7-840F-461A-A0F9-6E29F5C43F45"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10607:*:*:*:*:*:*" ,
"matchCriteriaId" : "9EB47A8C-7569-45C7-A7A9-4E8C898CE6D2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10608:*:*:*:*:*:*" ,
"matchCriteriaId" : "FBF8EED5-6575-41EC-9E5D-0BC0355AF0D1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10609:*:*:*:*:*:*" ,
"matchCriteriaId" : "3D0F1C6C-878B-4E5E-BE82-1FC0B17CEF3C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:10.6:10610:*:*:*:*:*:*" ,
"matchCriteriaId" : "C40C9186-B510-401C-B934-3432C80A38A1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:13.0:13000:*:*:*:*:*:*" ,
"matchCriteriaId" : "298E6401-A9A9-43B6-901F-327944E0AF94"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:13.0:13001:*:*:*:*:*:*" ,
"matchCriteriaId" : "0998F749-27E4-4C98-A027-939427640F8E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:13.0:13002:*:*:*:*:*:*" ,
"matchCriteriaId" : "05694BAB-3210-47A6-8FAD-5AC84FBAD240"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:13.0:13003:*:*:*:*:*:*" ,
"matchCriteriaId" : "DD0F5553-E56E-4DFC-BEE1-62872D078886"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://manageengine.com" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Product"
]
} ,
{
"url" : "https://www.manageengine.com/products/service-desk-msp/cve-2023-22964.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
}
]
}