CVE-2024-27310

MEDIUM

Zoho ManageEngine ASDSelfService Plus <6401 - DoS

Title source: llm
STIX 2.1

Description

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

Scores

CVSS v3 5.3
EPSS 0.0579
EPSS Percentile 90.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-90
Status published
Products (2)
zohocorp/manageengine_adselfservice_plus 6.4 6400
zohocorp/manageengine_adselfservice_plus < 6.4
Published May 27, 2024
Tracked Since Feb 18, 2026