Improper Authentication in Zoho ManageEngine Desktop Central - CVE-2021-44515

 

Improper Authentication in Zoho ManageEngine Desktop Central - CVE-2021-44515

Published: December 6, 2021 / Updated: December 7, 2021


Vulnerability identifier: #VU58523
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-44515
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests. A remote attacker can bypass authentication process and execute arbitrary code in the Desktop Central server.

Note, the vulnerability is being actively exploited in the wild.



Affected software

Zoho ManageEngine Desktop Central

How to mitigate CVE-2021-44515

Install update from vendor's website.

Zoho ManageEngine Desktop Central - addressed in versions 10.1.2127.18, 10.1.2137.3

External References

Related Security Bulletins