← KEV catalog
CISA known exploited vulnerability

CVE-2022-28810

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

SOURCE FACT

Zoho · ManageEngine

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

Required action

Apply updates per vendor instructions.

CISA notes

https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-28810.html; https://nvd.nist.gov/vuln/detail/CVE-2022-28810

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?