CVE-2021-40539
CRITICAL KEV RANSOMWARE NUCLEIManageEngine ADSelfService Plus CVE-2021-40539
Title source: metasploitDescription
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
Exploits (6)
nomisec
WORKING POC
2 stars
by Bu0uCat · remote
https://github.com/Bu0uCat/ADSelfService-Plus-RCE-CVE-2021-40539
metasploit
WORKING POC
EXCELLENT
by Antoine Cervoise, Wilfried Bécard, mr_me, wvu · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/manageengine_adselfservice_plus_cve_2021_40539.rb
Nuclei Templates (1)
Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution
CRITICALby daffainfo,pdteam
Shodan:
http.title:"manageengine" || http.title:"adselfservice plus"
FOFA:
title="manageengine" || title="adselfservice plus"
References (4)
Scores
CVSS v3
9.8
EPSS
0.9442
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2021-09-16
InTheWild.io
2021-09-09
ENISA EUVD
EUVD-2021-27714
Ransomware Use
Confirmed
CWE
CWE-706
Status
published
Products (2)
zohocorp/manageengine_adselfservice_plus
6.1 (9 CPE variants)
zohocorp/manageengine_adselfservice_plus
< 6.1
Published
Sep 07, 2021
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026