CVE-2021-40539 is a critical REST API authentication bypass vulnerability affecting Zoho ManageEngine ADSelfService Plus version 6113 and prior, leading to remote code execution. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication, allowing attackers full control over affected systems. It is actively exploited in the wild, including by known ransomware campaigns and state-backed APTs, with public exploit modules available in Metasploit and Nuclei. The vulnerability has garnered significant community discussion and media attention, highlighting its severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:-:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6100:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6101:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6102:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.