CVE-2022-28810 is a critical OS command injection vulnerability affecting Zoho ManageEngine ADSelfService Plus before build 6122, allowing remote authenticated administrators to execute arbitrary commands as SYSTEM. Its CVSS score of 6.8 (MEDIUM) belies its true risk, as the vulnerability is easily exploitable due to default administrator passwords and unsanitized password fields, enabling even partially authenticated attackers to inject commands. This flaw is actively exploited in the wild, with a Metasploit module available and significant community discussion, indicating a high likelihood of attack.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:-:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6100:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6101:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6102:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.