Record summary

CVE-2022-28810 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit. CISA lists CVE-2022-28810 in KEV.

Description

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 7, 2023 · CISA
VulnCheck KEV
Listed · Apr 14, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

1

Catalogued exploits

MetasploitManageEngine ADSelfService Plus Custom Script ExecutionMetasploit exploitby Andrew Iwamaye +3 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

6