CVE-2022-28810
악용 확인 Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
악용 여부
악용 확인
2023-03-07
2023-03-28
CISA 미확인
Zoho ManageEngine
심각도 (발행처 발표값)
보통6.8
3.1
NVD (미국 NIST)
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
악용 확률 (EPSS)
71.0%
70.97%
99.4%
2026-09-04
한국어 공식 권고
CISA 원문
Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.— CISA KEV · shortDescription 원문
Apply updates per vendor instructions.— CISA KEV · requiredAction 원문
취약점 설명 (NVD 원문)
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
CWE-78 CWE-798 CWE-798
이 페이지는 조치 지시가 아닙니다. 영향 범위와 패치 버전은 제품·구성에 따라 다르므로, 반드시 공급사 공식 권고와 NVD 원문의 참조 링크를 확인하세요.