Impact
The vulnerability in ManageEngine ADSelfService Plus permits bypass of the multi‑factor authentication mechanism, allowing an attacker to obtain authenticated sessions without the second factor. This weakness, identified as CWE‑290, undermines confidentiality and integrity by granting unintended access to protected resources and potentially enabling privilege escalation. The impact is that unauthorized users can act with the same privileges as legitimate users, exposing sensitive data and services.
Affected Systems
Zohocorp ManageEngine ADSelfService Plus versions prior to 6524 are affected. All installations running any earlier build should upgrade to a supported release. No additional vendor or product information is provided in the advisory.
Risk and Exploitability
The CVSS score of 7.1 marks the issue as high severity, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The advisory does not specify the attack vector; however, it is inferred that an attacker who can trigger or manipulate authentication requests—either remotely or from within the network—may bypass MFA, potentially accessing user accounts and sensitive data.
OpenCVE Enrichment