CVE-2023-35785 is a two-factor authentication (2FA) bypass vulnerability affecting numerous Zoho ManageEngine products, including Active Directory 360, ADAudit Plus, and ServiceDesk Plus, across various versions. An attacker can exploit this flaw to bypass 2FA using specific TOTP authenticators, provided they already possess a valid username and password for the target system. Rated with a CVSS score of 8.1 (HIGH), this vulnerability has a network attack vector and high impact on confidentiality, integrity, and availability. While the attack complexity is high due to the prerequisite of valid credentials, no user interaction is required once those are obtained. Currently, there is no evidence of active exploitation in the wild, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, suggesting low awareness and a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_ad360:*:*:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4300:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4302:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4303:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_ad360:4.3:4304:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.