6.5
CVSSv2

CVE-2022-29457

Published: 18/04/2022 Updated: 30/09/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Zoho ManageEngine ADSelfService Plus prior to 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine adselfservice plus 6.1

zohocorp manageengine adselfservice plus

zohocorp manageengine admanager plus 7.1

zohocorp manageengine admanager plus

zohocorp manageengine adaudit plus 7.0.0

zohocorp manageengine adaudit plus

zohocorp manageengine exchange reporter plus 5.7

zohocorp manageengine exchange reporter plus

Exploits

ManageEngine ADSelfService Plus build 6118 suffers from an NTLMv2 hash exposure vulnerability ...