Security Advisory

2FA bypass vulnerability fixed in ManageEngine AD360

Vulnerability details
Severity Medium
CVE ID CVE-2023-35785
Affected software versions Build 4315 and older
Fixed version Build 4316
Fixed on June 20, 2023

Details

A security vulnerability, CVE-2023-35785, leading to the bypass of 2FA during AD360 login, was found and fixed in build 4316. Please find the latest release notes here.

Impact

An authenticated user with admin privileges can bypass 2FA to access critical resources and perform unauthorized actions using AD360.

Steps to update

Update your AD360 instance to its latest build by installing the service pack.

Acknowledgements

This issue was reported by dalt4sec through the Zoho BugBounty program.