PT-2021-5330 · Zoho · Zoho Manageengine Servicedesk Plus

Published

2021-12-06

·

Updated

2022-07-12

·

CVE-2021-44526

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ServiceDesk Plus versions prior to 12003
Description The issue is related to authentication bypass in certain admin configurations, which can allow a remote attacker to bypass authentication procedures and gain unauthorized access to the device.
Recommendations For versions prior to 12003, update to version 12003 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06158
CVE-2021-44526

Affected Products

Zoho Manageengine Servicedesk Plus