PT-2022-12223 · Zoho · Zoho Manageengine Desktop Central
Published
2022-01-18
·
Updated
2022-07-12
·
CVE-2021-44757
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Desktop Central versions prior to 10.1.2137.9
Zoho ManageEngine Desktop Central MSP versions prior to 10.1.2137.9
Description
The issue allows attackers to bypass authentication, enabling them to read sensitive information or upload an arbitrary ZIP archive to the server. This can be exploited by a remote adversary to perform unauthorized actions in affected servers.
Recommendations
For Zoho ManageEngine Desktop Central versions prior to 10.1.2137.9, update to version 10.1.2137.9 or later.
For Zoho ManageEngine Desktop Central MSP versions prior to 10.1.2137.9, update to version 10.1.2137.9 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoho Manageengine Desktop Central