CVE-2023-22964: Zohocorp ManageEngine ServiceDesk Plus Msp
Critical severity, CVSS 9.1. EPSS: 2.4% chance of exploitation in the next 30 days.
Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.
Affected products
- Zohocorp ManageEngine ServiceDesk Plus Msp: version 10.6 only; version 13.0 only
Published 2023-01-20. Last modified 2026-06-17.