CVE-2022-28810
Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 6.8
- EPSS
- 70.4% 백분위 99.3% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.03.28
- 공개일
- 2022.04.18
CISA KEV에 등록된 실제 악용 확인 취약점
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
공급사 Zoho
제품 ManageEngine
영향 버전 n/a, < 6.1, 6.1
수정 버전 6.1
Apply updates per vendor instructions.
조치 기한: 2023.03.28CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE CWE-259, CWE-78, CWE-798
KEV 등록일 2023.03.07
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-28810.html; https://nvd.nist.gov/vuln/detail/CVE-2022-28810
EPSS 데이터 기준일 2026.06.27