PT-2021-5435 · Zoho · Zoho Manageengine Desktop Central
Published
2021-12-04
·
Updated
2025-10-31
·
CVE-2021-44515
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Desktop Central versions 10.1.2127.17 through 10.1.2137.2
Zoho ManageEngine Desktop Central version 10.1.2127.17 and earlier
Description
The issue is related to an authentication bypass vulnerability in Zoho ManageEngine Desktop Central, which can be exploited to execute remote code on the server. This vulnerability has been exploited in the wild. The estimated number of potentially affected devices is not specified.
Recommendations
For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18.
For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18.
For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
Exploit
Fix
Improper Authentication
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoho Manageengine Desktop Central