Fiche vulnérabilité
CVE-2023-32783 : faille élevée zohocorp manageengine adaudit plus (CVSS 7.5)
Description
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 août 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- zohocorp manageengine adaudit plus