Detection rules › Sigma
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
Detects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Initial Access | T1190 Exploit Public-Facing Application |
| Persistence | T1505.003 Server Software Component: Web Shell |
Rule body yaml
title: CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
id: fcbb4a77-f368-4945-b046-4499a1da69d1
status: test
description: Detects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
references:
- https://therecord.media/cisa-warns-of-zoho-server-zero-day-exploited-in-the-wild/
- https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html
- https://us-cert.cisa.gov/ncas/alerts/aa21-259a
author: Sittikorn S, Nuttakorn Tungpoonsup
date: 2021-09-10
modified: 2023-01-02
tags:
- attack.initial-access
- attack.t1190
- attack.persistence
- attack.t1505.003
- cve.2021-40539
- detection.emerging-threats
logsource:
category: webserver
definition: 'Must be collect log from \ManageEngine\ADSelfService Plus\logs'
detection:
selection:
cs-uri-query|contains:
- '/help/admin-guide/Reports/ReportGenerate.jsp'
- '/RestAPI/LogonCustomization'
- '/RestAPI/Connection'
condition: selection
falsepositives:
- Unknown
level: critical
Stages and Predicates
Stage 0: condition
selectionStage 1: selection
selection:
cs-uri-query|contains:
- '/help/admin-guide/Reports/ReportGenerate.jsp'
- '/RestAPI/LogonCustomization'
- '/RestAPI/Connection'
Indicators
Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.
| Field | Kind | Values |
|---|---|---|
cs-uri-query | match |
|