CVE-2023-35785: 
Zoho ManageEngine EventLog Analyzer 脆弱性の分析と軽減

概要

CVE-2023-35785 is a Two-Factor Authentication (2FA) bypass vulnerability affecting multiple Zoho ManageEngine products. The vulnerability was discovered in June 2023 and affects various versions of ManageEngine products including Active Directory 360, ADAudit Plus, ADManager Plus, and several others. The vulnerability specifically allows bypass of 2FA via TOTP authenticators, though it requires a valid pair of username and password to be exploited (Vendor Advisory).

技術的な詳細

The vulnerability has been assigned a CVSS v3.1 base score of 8.1 (HIGH) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability is classified under CWE-287 (Improper Authentication). The technical nature of the vulnerability involves the bypass of TOTP-based two-factor authentication mechanisms in affected ManageEngine products (NVD).

影響

If exploited, this vulnerability allows an adversary to bypass the two-factor authentication and take over the victim's account. This could lead to unauthorized access to critical resources and enable the attacker to perform unauthorized actions within the affected ManageEngine products (Vendor Advisory).

エクスプロイト可能性

The vulnerability requires a valid pair of username and password credentials to be exploited, which somewhat limits its exploitability. However, once these credentials are obtained, the 2FA mechanism can be bypassed via specific TOTP authenticators (NVD).

軽減策と回避策

Zoho has released patches for all affected products in June 2023. Organizations are strongly advised to upgrade to the latest builds of the affected products. The fixed versions vary by product, for example: Active Directory 360 - version 4316, ADAudit Plus - version 7203, ADManager Plus - version 7201, and others. ManageEngine On-Demand/cloud products are not affected by this vulnerability (Vendor Advisory).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 Zoho ManageEngine EventLog Analyzer 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2021-44228CRITICAL10
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:cisco:sd-wan_vmanage
はいはいDec 10, 2021
CVE-2023-35785HIGH8.1
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
いいえはいAug 28, 2023
CVE-2021-44832MEDIUM6.6
  • IBM Db2 logoIBM Db2
  • hive-container-v4.8.0
いいえはいDec 28, 2021
CVE-2021-45105MEDIUM5.9
  • IBM Db2 logoIBM Db2
  • openshift4::ose-logging-elasticsearch6@sha256:f1a53e3be27c714226869b259c8eed80ac797b0cb83fbc2d786a9bba383d9547_amd64
いいえはいDec 18, 2021
CVE-2026-92905MEDIUM5.3
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer
いいえはいSep 24, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者