CVE-2021-44515
Zoho Desktop Central Authentication Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
Zoho ManageEngine Desktop Central es vulnerable a una omisión de autenticación, conllevando a una ejecución de código remota en el servidor, como es explotada "in the wild" en diciembre de 2021. Para las versiones Enterprise 10.1.2127.17 y anteriores, actualice a 10.1.2127.18. Para las versiones 10.1.2128.0 a 10.1.2137.2 de Enterprise, actualice a 10.1.2137.3. Para las versiones de MSP 10.1.2127.17 y anteriores, actualice a 10.1.2127.18. Para las versiones de MSP 10.1.2128.0 a 10.1.2137.2, actualice a 10.1.2137.3
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-01 CVE Reserved
- 2021-12-10 Exploited in Wild
- 2021-12-12 CVE Published
- 2021-12-24 KEV Due Date
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-11-17 EPSS Updated
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/uscert/ncas/current-activity/2021/12/10/cisa-adds-thirteen-known-exploited-vulnerabilities-catalog | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.manageengine.com/products/desktop-central/cve-2021-44515-authentication-bypass-filter-configuration.html | 2024-08-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Manageengine Desktop Central Search vendor "Zohocorp" for product "Manageengine Desktop Central" | < 10.1.2127.18 Search vendor "Zohocorp" for product "Manageengine Desktop Central" and version " < 10.1.2127.18" | enterprise |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Desktop Central Search vendor "Zohocorp" for product "Manageengine Desktop Central" | < 10.1.2127.18 Search vendor "Zohocorp" for product "Manageengine Desktop Central" and version " < 10.1.2127.18" | managed_service_providers |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Desktop Central Search vendor "Zohocorp" for product "Manageengine Desktop Central" | >= 10.1.2128.0 <= 10.1.2137.3 Search vendor "Zohocorp" for product "Manageengine Desktop Central" and version " >= 10.1.2128.0 <= 10.1.2137.3" | enterprise |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Desktop Central Search vendor "Zohocorp" for product "Manageengine Desktop Central" | >= 10.1.2128.0 < 10.1.2137.3 Search vendor "Zohocorp" for product "Manageengine Desktop Central" and version " >= 10.1.2128.0 < 10.1.2137.3" | managed_service_providers |
Affected
|