Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22964


Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.


Published

2023-01-20T17:15:11.003

Last Modified

2025-04-03T15:15:43.047

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-287
  • Type: Secondary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 10.6 Yes
Application zohocorp manageengine_servicedesk_plus_msp 13.0 Yes
Application zohocorp manageengine_servicedesk_plus_msp 13.0 Yes
Application zohocorp manageengine_servicedesk_plus_msp 13.0 Yes
Application zohocorp manageengine_servicedesk_plus_msp 13.0 Yes

References