CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit


Description

Detects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).

Query · sigma

selection:
  cs-uri-query|contains:
  - /help/admin-guide/Reports/ReportGenerate.jsp
  - /RestAPI/LogonCustomization
  - /RestAPI/Connection
condition: selection

Known false positives

  • Unknown
Raw source CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
id: fcbb4a77-f368-4945-b046-4499a1da69d1
status: test
description: Detects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
references:
    - https://therecord.media/cisa-warns-of-zoho-server-zero-day-exploited-in-the-wild/
    - https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html
    - https://us-cert.cisa.gov/ncas/alerts/aa21-259a
author: Sittikorn S, Nuttakorn Tungpoonsup
date: 2021-09-10
modified: 2023-01-02
tags:
    - attack.initial-access
    - attack.t1190
    - attack.persistence
    - attack.t1505.003
    - cve.2021-40539
    - detection.emerging-threats
logsource:
    category: webserver
    definition: 'Must be collect log from \ManageEngine\ADSelfService Plus\logs'
detection:
    selection:
        cs-uri-query|contains:
            - '/help/admin-guide/Reports/ReportGenerate.jsp'
            - '/RestAPI/LogonCustomization'
            - '/RestAPI/Connection'
    condition: selection
falsepositives:
    - Unknown
level: critical

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.