Unauthorized Password Reset in Zoho Remote Access Plus Server
CVE-2021-42955
7.3HIGH
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 17 November 2021
What is CVE-2021-42955?
The Zoho Remote Access Plus Server is vulnerable to unauthorized password resets due to a flaw in its password reset mechanism. This allows non-admin Windows users to reset the password of the Remote Access Plus Server Admin account without proper authorization, potentially leading to unauthorized access and manipulation of sensitive server configurations.