Detects CVE-2021-40539 Zoho ManageEngine ADSelfService Plus REST API Auth Bypass Attempts
Flags web requests targeting ADSelfService Plus REST API paths linked to CVE-2021-40539 authentication bypass.
FreeUnreviewedSigmacriticalv1
detects-cve-2021-40539-zoho-manageengine-adselfservice-plus-rest-api-auth-bypass-fcbb4a77
title: Detects CVE-2021-40539 Zoho ManageEngine ADSelfService Plus REST API Auth Bypass Attempts
id: 0e68c29a-2994-4dea-93fe-0f62c0b49bea
status: test
description: This rule matches web requests whose URI query contains paths associated with an authentication bypass against the ADSelfService Plus REST API (CVE-2021-40539). Such exploitation matters because it can allow unauthorized access by bypassing authentication controls. The detection relies on webserver telemetry that records request URLs/queries, specifically matching the presence of targeted REST API and report-generation parameters in the query string.
references:
- https://therecord.media/cisa-warns-of-zoho-server-zero-day-exploited-in-the-wild/
- https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html
- https://us-cert.cisa.gov/ncas/alerts/aa21-259a
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-40539/web_cve_2021_40539_manageengine_adselfservice_exploit.yml
author: Sittikorn S, Nuttakorn Tungpoonsup, Huntrule Team
date: 2021-09-10
modified: 2023-01-02
tags:
- attack.initial-access
- attack.t1190
- attack.persistence
- attack.t1505.003
- cve.2021-40539
- detection.emerging-threats
logsource:
category: webserver
definition: Must be collect log from \ManageEngine\ADSelfService Plus\logs
detection:
selection:
cs-uri-query|contains:
- /help/admin-guide/Reports/ReportGenerate.jsp
- /RestAPI/LogonCustomization
- /RestAPI/Connection
condition: selection
falsepositives:
- Unknown
level: critical
license: DRL-1.1
related:
- id: fcbb4a77-f368-4945-b046-4499a1da69d1
type: derived
What it detects
This rule matches web requests whose URI query contains paths associated with an authentication bypass against the ADSelfService Plus REST API (CVE-2021-40539). Such exploitation matters because it can allow unauthorized access by bypassing authentication controls. The detection relies on webserver telemetry that records request URLs/queries, specifically matching the presence of targeted REST API and report-generation parameters in the query string.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.