CVE-2022-28810
Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
Record summary
CVE-2022-28810 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit. CISA lists CVE-2022-28810 in KEV.
Description
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Mar 7, 2023 · CISA
- VulnCheck KEV
- Listed · Apr 14, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ManageEngineBrowse Zoho / ManageEngine | CISA | Version data not supplied | |