Medium severity5.4NVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026
CVE-2023-41904
CVE-2023-41904
Description
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*range: <7.2
- cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.2:7200:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.2:7201:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.2:7202:*:*:*:*:*:*
- Zoho/ManageEngine ADManager Plusdescription
- Range: <7203
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.