Improper Authentication in Zoho ManageEngine ServiceDesk Plus - CVE-2021-44077
Published: December 3, 2021 / Updated: September 29, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system..
The vulnerability exists due to missing authentication, related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration. A remote non-authenticated attacker can send a specially crafted request to the API endpoint, bypass authentication process and execute arbitrary code on the system.
Affected software
How to mitigate CVE-2021-44077
Links to Public Exploits and PoC-codes
- Exploit #8415 - Golang-CVE-2021-44077-POC (Golang Proof of Concept Exploit for CVE-2021-44077: PreAuth RCE in ManageEngine ServiceDesk Plus < 11306) (September 29, 2022)
- Exploit #7199 - ManageEngine ServiceDesk Plus CVE-2021-44077 (December 23, 2021)
- Exploit #7119 - CVE-2021-44077 (Proof of Concept Exploit for ManageEngine ServiceDesk Plus CVE-2021-44077) (December 8, 2021)
External References
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vulnerability-in-servicedesk-plus-versions-up-to-11305-22-11-2021
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-authentication-bypass-vulnerability-in-servicedesk-plus-versions-11138-and-above
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vulnerability-in-servicedesk-plus-msp-versions-10527-till-10529
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vulnerability-in-supportcenter-plus-versions-11012-and-11013