CVE-2024-0252

HIGH

ManageEngine ADSelfService Plus <= 6401 - Authenticated Remote Code Execution in Load Balancer Component

Title source: llm
STIX 2.1

Description

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

Scores

CVSS v3 8.8
EPSS 0.2915
EPSS Percentile 96.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
zohocorp/manageengine_adselfservice_plus 6.4 6400 (2 CPE variants)
zohocorp/manageengine_adselfservice_plus < 6.4
Published Jan 11, 2024
Tracked Since Feb 18, 2026