CVE-2021-40539
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
Description
CVE-2021-40539 is a critical authentication bypass vulnerability in Zoho ManageEngine ADSelfService Plus, a self-service password management and single sign-on solution. The vulnerability affects the REST API URLs in ADSelfService Plus version 6113 and prior, allowing unauthenticated attackers to bypass authentication and achieve remote code execution on the target system. CISA has added CVE-2021-40539 to its Known Exploited Vulnerabilities catalog and has confirmed its use in ransomware campaigns. With an EPSS score of 94.42% (99.98th percentile), this Zoho ManageEngine vulnerability represents one of the most actively exploited security flaws in enterprise identity management software.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine adselfservice plus | < 6.1; 6.1 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/165085/ManageEngine-ADSelfService-Plus-Authentication-Bypass-Code-Execution.html(Exploit, Third Party Advisory, VDB Entry)
- https://www.manageengine.com(Product)
- https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40539(US Government Resource)
Weakness Type
CWE-706: Use of Incorrectly-Resolved Name or Reference
CWE-706 occurs when software uses a name or reference to access a resource, but the name or reference resolves to a different resource than intended. In the case of CVE-2021-40539, this weakness manifests in the REST API of Zoho ManageEngine ADSelfService Plus, where improperly resolved URL references allow attackers to bypass authentication mechanisms entirely.
Learn more: CWE-706 — Use of Incorrectly-Resolved Name or Reference
Impact Analysis
CVE-2021-40539 carries a CVSS 3.1 score of 9.8 (CRITICAL), reflecting the maximum exploitability and impact characteristics. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication and no user interaction, making it trivially exploitable by any attacker with network access to the ADSelfService Plus instance. Successful exploitation results in complete compromise of confidentiality, integrity, and availability, granting the attacker full control over the affected system. The EPSS score of 94.42% places this vulnerability in the 99.98th percentile, indicating near-certain exploitation activity. Critically, CISA has confirmed that CVE-2021-40539 is known to be used in ransomware campaigns, significantly elevating the risk for organizations that have not applied patches.
Exploit Maturity
CVE-2021-40539 has a highly mature exploit landscape. CISA has confirmed active exploitation in the wild through its KEV catalog listing, and this vulnerability is known to be used in ransomware campaigns, making it a top-priority remediation target. Public exploit code is available via Packet Storm Security, significantly lowering the barrier to exploitation. The EPSS score of 94.42% (99.98th percentile) indicates near-certain exploitation activity, consistent with widespread targeting by both state-sponsored and cybercriminal threat actors. Federal agencies were required to remediate this vulnerability by 2021-11-17 per CISA binding operational directive.
Remediation
- Apply updates immediately as mandated by CISA KEV: Apply updates per vendor instructions. Upgrade Zoho ManageEngine ADSelfService Plus to a version later than build 6114 using the official patch from the ManageEngine security advisory.
- Verify that all instances of ADSelfService Plus (versions 6113 and prior, including all 6.1.x releases) have been updated. Check the build number in the ADSelfService Plus admin console under Settings > Product Info.
- If immediate patching is not possible, restrict network access to the ADSelfService Plus REST API endpoints. Block external access to port 443/8443 where ADSelfService Plus is hosted, and limit access to trusted administrative IP ranges only.
- Conduct a thorough forensic investigation of affected systems, reviewing web server access logs for suspicious REST API calls, checking for webshells or unauthorized files in the application directory, and scanning for indicators of compromise (IOCs) published by CISA.
- Implement long-term hardening measures including network segmentation of identity management infrastructure, deploying a web application firewall (WAF) in front of ADSelfService Plus, enabling comprehensive audit logging, and regularly reviewing API authentication mechanisms for similar bypass vulnerabilities.
Technical Details
CVE-2021-40539 exploits a flaw classified under CWE-706 (Use of Incorrectly-Resolved Name or Reference) in the REST API authentication layer of Zoho ManageEngine ADSelfService Plus version 6113 and prior. The vulnerability allows attackers to craft specially formatted REST API requests that bypass the authentication checks, gaining unauthorized access to privileged API endpoints. The CVSS vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H confirms that exploitation is network-based with low complexity, requires no privileges or user interaction, and results in complete compromise of the target system. Once authenticated checks are bypassed, the attacker can leverage the API to upload malicious code and achieve remote code execution with the privileges of the ADSelfService Plus service account, typically running with elevated system permissions.
Frequently Asked Questions
Is CVE-2021-40539 being actively exploited?
Yes. CVE-2021-40539 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming widespread active exploitation. CISA has also confirmed that this vulnerability is known to be used in ransomware campaigns. The EPSS score of 94.42% (99.98th percentile) indicates near-certain exploitation activity.
What products are affected by CVE-2021-40539?
CVE-2021-40539 affects Zoho ManageEngine ADSelfService Plus version 6113 and all prior versions, including the 6.1.x release line. Organizations using any version of ADSelfService Plus at or below build 6113 should treat their systems as vulnerable.
How do I fix CVE-2021-40539?
Upgrade Zoho ManageEngine ADSelfService Plus to a version later than build 6114 by applying the official patch from ManageEngine. If immediate patching is not possible, restrict external access to the ADSelfService Plus REST API and conduct forensic analysis for indicators of compromise.
How severe is CVE-2021-40539?
CVE-2021-40539 has a CVSS 3.1 score of 9.8 (CRITICAL) and an EPSS score in the 99.98th percentile. It requires no authentication, is remotely exploitable, and is confirmed to be used in ransomware attacks, making it one of the most dangerous vulnerabilities in enterprise identity management software.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.