Fiche vulnérabilité
CVE-2023-22964 : faille critique zohocorp manageengine servicedesk plus… (CVSS 9.1)
Description
Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.
En bref
- Sévérité
- Critique (CVSS 9.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 20 janv. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- zohocorp manageengine servicedesk plus msp