CVE-2024-27310

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.4:6400:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*

History

27 Nov 2024, 16:25

Type Values Removed Values Added
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.4:6400:*:*:*:*:*:*
References () https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-27310.html - () https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-27310.html - Vendor Advisory
First Time Zohocorp
Zohocorp manageengine Adselfservice Plus

07 Oct 2024, 20:15

Type Values Removed Values Added
Summary Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP query. Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

27 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-27 18:15

Updated : 2024-11-27 16:25


NVD link : CVE-2024-27310

Mitre link : CVE-2024-27310


JSON object : View

Products Affected

zohocorp

  • manageengine_adselfservice_plus