CVE Vulnerabilities

CVE-2023-26601

Uncontrolled Resource Consumption

Published: Mar 06, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

Name Vendor Start Version End Version
Manageengine_assetexplorer Zohocorp * 6.9 (excluding)
Manageengine_assetexplorer Zohocorp 6.9 (including) 6.9 (including)
Manageengine_assetexplorer Zohocorp 6.9-6900 (including) 6.9-6900 (including)
Manageengine_assetexplorer Zohocorp 6.9-6901 (including) 6.9-6901 (including)
Manageengine_assetexplorer Zohocorp 6.9-6902 (including) 6.9-6902 (including)
Manageengine_assetexplorer Zohocorp 6.9-6903 (including) 6.9-6903 (including)
Manageengine_assetexplorer Zohocorp 6.9-6904 (including) 6.9-6904 (including)
Manageengine_assetexplorer Zohocorp 6.9-6905 (including) 6.9-6905 (including)
Manageengine_assetexplorer Zohocorp 6.9-6906 (including) 6.9-6906 (including)
Manageengine_assetexplorer Zohocorp 6.9-6907 (including) 6.9-6907 (including)
Manageengine_assetexplorer Zohocorp 6.9-6908 (including) 6.9-6908 (including)
Manageengine_assetexplorer Zohocorp 6.9-6909 (including) 6.9-6909 (including)
Manageengine_assetexplorer Zohocorp 6.9-6950 (including) 6.9-6950 (including)
Manageengine_assetexplorer Zohocorp 6.9-6951 (including) 6.9-6951 (including)
Manageengine_assetexplorer Zohocorp 6.9-6952 (including) 6.9-6952 (including)
Manageengine_assetexplorer Zohocorp 6.9-6953 (including) 6.9-6953 (including)
Manageengine_assetexplorer Zohocorp 6.9-6954 (including) 6.9-6954 (including)
Manageengine_assetexplorer Zohocorp 6.9-6955 (including) 6.9-6955 (including)
Manageengine_assetexplorer Zohocorp 6.9-6956 (including) 6.9-6956 (including)
Manageengine_assetexplorer Zohocorp 6.9-6957 (including) 6.9-6957 (including)
Manageengine_assetexplorer Zohocorp 6.9-6970 (including) 6.9-6970 (including)
Manageengine_assetexplorer Zohocorp 6.9-6971 (including) 6.9-6971 (including)
Manageengine_assetexplorer Zohocorp 6.9-6972 (including) 6.9-6972 (including)
Manageengine_assetexplorer Zohocorp 6.9-6973 (including) 6.9-6973 (including)
Manageengine_assetexplorer Zohocorp 6.9-6974 (including) 6.9-6974 (including)
Manageengine_assetexplorer Zohocorp 6.9-6975 (including) 6.9-6975 (including)
Manageengine_assetexplorer Zohocorp 6.9-6976 (including) 6.9-6976 (including)
Manageengine_assetexplorer Zohocorp 6.9-6977 (including) 6.9-6977 (including)
Manageengine_assetexplorer Zohocorp 6.9-6978 (including) 6.9-6978 (including)
Manageengine_assetexplorer Zohocorp 6.9-6979 (including) 6.9-6979 (including)
Manageengine_assetexplorer Zohocorp 6.9-6980 (including) 6.9-6980 (including)
Manageengine_assetexplorer Zohocorp 6.9-6981 (including) 6.9-6981 (including)
Manageengine_assetexplorer Zohocorp 6.9-6982 (including) 6.9-6982 (including)
Manageengine_assetexplorer Zohocorp 6.9-6983 (including) 6.9-6983 (including)
Manageengine_assetexplorer Zohocorp 6.9-6984 (including) 6.9-6984 (including)
Manageengine_assetexplorer Zohocorp 6.9-6985 (including) 6.9-6985 (including)
Manageengine_assetexplorer Zohocorp 6.9-6986 (including) 6.9-6986 (including)
Manageengine_assetexplorer Zohocorp 6.9-6987 (including) 6.9-6987 (including)
Manageengine_servicedesk_plus Zohocorp * 14.1 (excluding)
Manageengine_servicedesk_plus Zohocorp 14.1 (including) 14.1 (including)
Manageengine_servicedesk_plus Zohocorp 14.1-14100 (including) 14.1-14100 (including)
Manageengine_servicedesk_plus Zohocorp 14.1-14101 (including) 14.1-14101 (including)
Manageengine_servicedesk_plus Zohocorp 14.1-14102 (including) 14.1-14102 (including)
Manageengine_servicedesk_plus Zohocorp 14.1-14103 (including) 14.1-14103 (including)
Manageengine_servicedesk_plus_msp Zohocorp * 14.0 (excluding)
Manageengine_servicedesk_plus_msp Zohocorp 14.0-14000 (including) 14.0-14000 (including)
Manageengine_supportcenter_plus Zohocorp * 14.0 (excluding)
Manageengine_supportcenter_plus Zohocorp 14.0-14000 (including) 14.0-14000 (including)

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References