PT-2021-5435 · Zoho · Zoho Manageengine Desktop Central

Published

2021-12-04

·

Updated

2025-10-31

·

CVE-2021-44515

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Desktop Central versions 10.1.2127.17 through 10.1.2137.2 Zoho ManageEngine Desktop Central version 10.1.2127.17 and earlier
Description The issue is related to an authentication bypass vulnerability in Zoho ManageEngine Desktop Central, which can be exploited to execute remote code on the server. This vulnerability has been exploited in the wild. The estimated number of potentially affected devices is not specified.
Recommendations For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.

Exploit

Fix

Improper Authentication

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06278
BDU:2023-01121
CVE-2021-44515

Affected Products

Zoho Manageengine Desktop Central