Vulnerability Intelligence Report
CVE-2023-22964
Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:2.45%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-287 ↗CWE-287 Improper Authentication
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| zohocorp | manageengine_servicedesk_plus_msp | 10.6, 13.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
2.448%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2023-01-11T00:00:00 |
| Published | 2023-01-20T00:00:00 |
| Last Updated | 2025-04-03T15:07:12 |
Community Chatter & Buzz