Detects CVE-2021-40539 Zoho ManageEngine ADSelfService Plus REST API Auth Bypass Attempts

Flags web requests targeting ADSelfService Plus REST API paths linked to CVE-2021-40539 authentication bypass.

FreeUnreviewedSigmacriticalv1
title: Detects CVE-2021-40539 Zoho ManageEngine ADSelfService Plus REST API Auth Bypass Attempts
id: 0e68c29a-2994-4dea-93fe-0f62c0b49bea
status: test
description: This rule matches web requests whose URI query contains paths associated with an authentication bypass against the ADSelfService Plus REST API (CVE-2021-40539). Such exploitation matters because it can allow unauthorized access by bypassing authentication controls. The detection relies on webserver telemetry that records request URLs/queries, specifically matching the presence of targeted REST API and report-generation parameters in the query string.
references:
  - https://therecord.media/cisa-warns-of-zoho-server-zero-day-exploited-in-the-wild/
  - https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html
  - https://us-cert.cisa.gov/ncas/alerts/aa21-259a
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-40539/web_cve_2021_40539_manageengine_adselfservice_exploit.yml
author: Sittikorn S, Nuttakorn Tungpoonsup, Huntrule Team
date: 2021-09-10
modified: 2023-01-02
tags:
  - attack.initial-access
  - attack.t1190
  - attack.persistence
  - attack.t1505.003
  - cve.2021-40539
  - detection.emerging-threats
logsource:
  category: webserver
  definition: Must be collect log from \ManageEngine\ADSelfService Plus\logs
detection:
  selection:
    cs-uri-query|contains:
      - /help/admin-guide/Reports/ReportGenerate.jsp
      - /RestAPI/LogonCustomization
      - /RestAPI/Connection
  condition: selection
falsepositives:
  - Unknown
level: critical
license: DRL-1.1
related:
  - id: fcbb4a77-f368-4945-b046-4499a1da69d1
    type: derived

What it detects

This rule matches web requests whose URI query contains paths associated with an authentication bypass against the ADSelfService Plus REST API (CVE-2021-40539). Such exploitation matters because it can allow unauthorized access by bypassing authentication controls. The detection relies on webserver telemetry that records request URLs/queries, specifically matching the presence of targeted REST API and report-generation parameters in the query string.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.