CVE-2021-28958
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 73%
exploitation probability
73%top 1% of all CVEs
observed exploitation
nono source reports it
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
Affected products
n/a · n/aReferences
https://blog.stmcyber.com/vulns/cve-2021-28958/https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6102-released-with-an-important-security-fix-21-3-2021https://www.manageengine.comhttps://www.manageengine.com/products/self-service-password/release-notes.html#6102