Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
History

Tue, 04 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2021-12-10'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-04T19:30:05.712Z

Reserved: 2021-12-01T00:00:00.000Z

Link: CVE-2021-44515

cve-icon Vulnrichment

Updated: 2024-08-04T04:25:16.647Z

cve-icon NVD

Status : Modified

Published: 2021-12-12T05:15:07.997

Modified: 2025-02-04T20:15:44.797

Link: CVE-2021-44515

cve-icon Redhat

No data.