CVE-2021-40539

CRITICAL KEV RANSOMWARE NUCLEI

ManageEngine ADSelfService Plus CVE-2021-40539

Title source: metasploit

Description

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

Exploits (6)

nomisec WORKING POC 47 stars
by synacktiv · remote
https://github.com/synacktiv/CVE-2021-40539
nomisec WORKING POC 2 stars
by Bu0uCat · remote
https://github.com/Bu0uCat/ADSelfService-Plus-RCE-CVE-2021-40539
nomisec STUB 2 stars
by DarkSprings · poc
https://github.com/DarkSprings/CVE-2021-40539
nomisec WORKING POC 1 stars
by lpyydxs · remote
https://github.com/lpyydxs/CVE-2021-40539
nomisec WORKING POC
by lpyzds · remote
https://github.com/lpyzds/CVE-2021-40539
metasploit WORKING POC EXCELLENT
by Antoine Cervoise, Wilfried Bécard, mr_me, wvu · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/manageengine_adselfservice_plus_cve_2021_40539.rb

Nuclei Templates (1)

Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution
CRITICALby daffainfo,pdteam
Shodan: http.title:"manageengine" || http.title:"adselfservice plus"
FOFA: title="manageengine" || title="adselfservice plus"

Scores

CVSS v3 9.8
EPSS 0.9442
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-09-16
InTheWild.io 2021-09-09
ENISA EUVD EUVD-2021-27714
Ransomware Use Confirmed
CWE
CWE-706
Status published
Products (2)
zohocorp/manageengine_adselfservice_plus 6.1 (9 CPE variants)
zohocorp/manageengine_adselfservice_plus < 6.1
Published Sep 07, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026