S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-29084 Scanner

Detects 'OS Command Injection' vulnerability in Zoho ManageEngine ADManager Plus affects v. before 7181.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-29084
7.2
CVSShigh
Exploitable remotely over the internet · requires high privileges.

Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Zoho ManageEngine ADManager Plus is a popular web-based Active Directory management and reporting tool designed to streamline and simplify the management of heterogeneous IT environments. With ADManager Plus, IT administrators can perform various tasks such as user provisioning, password reset, permissions management, group policy setting, and more.

However, the software is not without its vulnerabilities, and in particular, the CVE-2023-29084 vulnerability has recently been detected. This vulnerability allows authenticated users to exploit command injection via Proxy settings, which can result in unauthorized access and the potential compromise of the entire Active Directory infrastructure.

When exploited, this vulnerability can give attackers the ability to execute arbitrary commands on the server, which may allow them to access sensitive data, install malware, or perform other malicious activities. The consequences of a successful attack can range from the theft of sensitive information to the complete compromise of an organization’s entire IT infrastructure.

Thanks to the pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets, including ADManager Plus. With comprehensive vulnerability scanning and reporting tools, as well as detailed remediation steps, s4e.io is an invaluable resource for IT administrators looking to secure their organization’s critical IT assets. By staying informed and taking proactive measures, organizations can effectively mitigate the risk of vulnerabilities and protect their assets against potential cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, IT administrators can take several precautions, including:

  • Update to the latest version of ADManager Plus, which fixes the vulnerability
  • Implement network segmentation to limit the scope of the attack
  • Use intrusion detection and prevention systems to detect and prevent such attacks
  • Regularly review and monitor Proxy settings and logs to detect any suspicious activities
  • Train employees on cybersecurity awareness and best practices

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.