CVE Vulnerabilities

CVE-2021-44757

Published: Jan 18, 2022 | Modified: Jul 12, 2022
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.

Affected Software

Name Vendor Start Version End Version
Manageengine_desktop_central Zohocorp * 10.1.2137.9 (excluding)
Manageengine_desktop_central_managed_service_providers Zohocorp * 10.1.2137.9 (excluding)

References