CVE Vulnerabilities

CVE-2022-36413

Improper Restriction of Excessive Authentication Attempts

Published: Mar 23, 2023 | Modified: Mar 30, 2023
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.

Weakness

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

Affected Software

Name Vendor Start Version End Version
Manageengine_adselfservice_plus Zohocorp * 6.2 (excluding)
Manageengine_adselfservice_plus Zohocorp 6.2-6200 (including) 6.2-6200 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6201 (including) 6.2-6201 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6202 (including) 6.2-6202 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6203 (including) 6.2-6203 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6204 (including) 6.2-6204 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6205 (including) 6.2-6205 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6206 (including) 6.2-6206 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6207 (including) 6.2-6207 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6208 (including) 6.2-6208 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6209 (including) 6.2-6209 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6210 (including) 6.2-6210 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6211 (including) 6.2-6211 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6212 (including) 6.2-6212 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6213 (including) 6.2-6213 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6214 (including) 6.2-6214 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6215 (including) 6.2-6215 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6216 (including) 6.2-6216 (including)
Manageengine_adselfservice_plus Zohocorp 6.2-6217 (including) 6.2-6217 (including)

Potential Mitigations

  • Common protection mechanisms include:

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

  • Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]

References