CVE Vulnerabilities

CVE-2021-44757

Published: Jan 18, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.

Affected Software

NameVendorStart VersionEnd Version
Manageengine_desktop_centralZohocorp*10.1.2137.9 (excluding)
Manageengine_desktop_central_managed_service_providersZohocorp*10.1.2137.9 (excluding)

References