{"cveID":"CVE-2021-40539","vendorProject":"Zoho","product":"ManageEngine","vulnerabilityName":"Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability","dateAdded":"2021-11-03","shortDescription":"Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2021-11-17","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-40539","cwes":["CWE-55"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1003","technique_name_at_mapping":"OS Credential Dumping","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1003.003","technique_name_at_mapping":"NTDS","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1027","technique_name_at_mapping":"Obfuscated Files or Information","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1047","technique_name_at_mapping":"Windows Management Instrumentation","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1070.004","technique_name_at_mapping":"File Deletion","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1087.002","technique_name_at_mapping":"Domain Account","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1136","technique_name_at_mapping":"Create Account","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1140","technique_name_at_mapping":"Deobfuscate/Decode Files or Information","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1218","technique_name_at_mapping":"System Binary Proxy Execution","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1505.003","technique_name_at_mapping":"Web Shell","mapping_type":"primary_impact","capability_group":"auth_bypass","comments":"CVE-2021-40539 is an authentication bypass vulnerability affecting representational state transfer (REST) application programming interface (API) URLs that could enable remote code execution. Successful exploitation of the vulnerability allows an attacker to place webshells, which enable the adversary to conduct post-exploitation activities, such as compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives and Active Directory files.\n\n","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1505.003","technique_name_at_mapping":"Web Shell","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1560.001","technique_name_at_mapping":"Archive via Utility","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-40539","technique":"T1573.001","technique_name_at_mapping":"Symmetric Cryptography","mapping_type":"secondary_impact","capability_group":"auth_bypass","comments":"This is an authentication bypass vulnerability that can enable remote code execution. \n\nNumerous post-exploitation impacts by threat actors are detailed in the referenced CISA report.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"OS Credential Dumping","name_at_mapping":"OS Credential Dumping","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":37,"has_detection_strategy":true},{"id":"T1003.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"NTDS","name_at_mapping":"NTDS","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":24,"has_detection_strategy":true},{"id":"T1027","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Obfuscated Files or Information","name_at_mapping":"Obfuscated Files or Information","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":94,"has_detection_strategy":true},{"id":"T1047","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Windows Management Instrumentation","name_at_mapping":"Windows Management Instrumentation","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":52,"has_detection_strategy":true},{"id":"T1070.004","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"File Deletion","name_at_mapping":"File Deletion","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":15,"has_detection_strategy":true},{"id":"T1087.002","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Domain Account","name_at_mapping":"Domain Account","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":21,"has_detection_strategy":true},{"id":"T1136","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Create Account","name_at_mapping":"Create Account","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":3,"has_detection_strategy":true},{"id":"T1140","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Deobfuscate/Decode Files or Information","name_at_mapping":"Deobfuscate/Decode Files or Information","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":18,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1218","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"System Binary Proxy Execution","name_at_mapping":"System Binary Proxy Execution","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":153,"has_detection_strategy":true},{"id":"T1505.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Shell","name_at_mapping":"Web Shell","renamed":false,"revoked_by":null,"mapping_types":["primary_impact","secondary_impact"],"sigma_rule_count":35,"has_detection_strategy":true},{"id":"T1560.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Archive via Utility","name_at_mapping":"Archive via Utility","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":17,"has_detection_strategy":true},{"id":"T1573.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Symmetric Cryptography","name_at_mapping":"Symmetric Cryptography","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":["6702b13c-e421-44cc-ab33-42cc25570f11","fcbb4a77-f368-4945-b046-4499a1da69d1"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}