PT-2022-12223 · Zoho · Zoho Manageengine Desktop Central

Published

2022-01-18

·

Updated

2022-07-12

·

CVE-2021-44757

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Desktop Central versions prior to 10.1.2137.9 Zoho ManageEngine Desktop Central MSP versions prior to 10.1.2137.9
Description The issue allows attackers to bypass authentication, enabling them to read sensitive information or upload an arbitrary ZIP archive to the server. This can be exploited by a remote adversary to perform unauthorized actions in affected servers.
Recommendations For Zoho ManageEngine Desktop Central versions prior to 10.1.2137.9, update to version 10.1.2137.9 or later. For Zoho ManageEngine Desktop Central MSP versions prior to 10.1.2137.9, update to version 10.1.2137.9 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-44757

Affected Products

Zoho Manageengine Desktop Central