CVE-2021-44757

Severity
9.1CRITICAL
EPSS
41.2%
top 2.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateJan 19

Description

Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

🔴Vulnerability Details

2
GHSA
GHSA-gqgc-m3vm-cxhj: Zoho ManageEngine Desktop Central before 102022-01-19
CVEList
CVE-2021-44757: Zoho ManageEngine Desktop Central before 102022-01-18
CVE-2021-44757 (CRITICAL CVSS 9.1) | Zoho ManageEngine Desktop Central b | cvebase.io