HTTP: Zoho ManageEngine ADManager Plus PasswordExpiryAction Unrestricted File Upload

This signature detects attempts to exploit a known vulnerability against Zoho ManageEngine ADManager Plus. A successful attack can lead to arbitrary file upload and arbitrary code execution.

Extended Description

Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

Affected Products

Zohocorp manageengine_admanager_plus

Short Name
HTTP:CTS:ZOHO-ADMGR-FILEUPLD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ADManager CVE-2021-20130 CVE-2021-37539 CVE-2021-37918 CVE-2021-37919 CVE-2021-37921 CVE-2021-37923 File ManageEngine PasswordExpiryAction Plus Unrestricted Upload Zoho
Release Date
01/04/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3657
False Positive
Unknown
Vendors

Zohocorp

CVSS Score

6.5

7.5

Found a potential security threat?