EXPOSURES › CVE-2022-28810
CVE-2022-28810
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
Zoho's ManageEngine ADSelfService Plus exposed RCE due to unpatched vulnerability during password change/reset, exploited in the wild.
Zoho ManageEngine ADSelfService Plus had an unpatched vulnerability that allowed remote code execution during password changes or resets, leading to its exploitation in the wild.
Shame score — Pattern of unpatched vulnerabilities and poor security posture in Zoho ManageEngine products.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.