Skip to content
COOEY

EXPOSURES › CVE-2022-28810

CVE-2022-28810

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-03-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-28810 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Zoho's ManageEngine ADSelfService Plus exposed RCE due to unpatched vulnerability during password change/reset, exploited in the wild.

Zoho ManageEngine ADSelfService Plus had an unpatched vulnerability that allowed remote code execution during password changes or resets, leading to its exploitation in the wild.

Shame score — Pattern of unpatched vulnerabilities and poor security posture in Zoho ManageEngine products.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.