TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-44077

CRITICALCISA KEV
9.8

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie11/29/2021
Derniere modification10/31/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurZoho
ProduitManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus
Nom vulnerabiliteZoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
Date ajout KEV2021-12-01
Date limite remediation2021-12-15
Utilise dans ransomwareUnknown

Produits affectes

zohocorp:manageengine_servicedesk_pluszohocorp:manageengine_servicedesk_plus_mspzohocorp:manageengine_supportcenter_plus

Faiblesses (CWE)

CWE-306CWE-306

References

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.