CRITICAL

CVE-2021-44077

Zohocorp Manageengine Servicedesk Plus 2021-11-29 CVSS v3.1
CVSS
9.8
KEV

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

Summary dbcve.org

Unauthenticated remote code execution in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus via the /RestAPI servlet path combined with the ImportTechnicians action in the Apache Struts configuration. A remote attacker without credentials can send crafted requests to this endpoint to achieve code execution on the underlying host.

Mitigation

Upgrade affected ManageEngine installations to the fixed versions: ServiceDesk Plus 11306 or later, ServiceDesk Plus MSP 10530 or later, and SupportCenter Plus 11014 or later. Apply the vendor patch promptly given the critical severity and unauthenticated attack vector, and review server logs for prior exploitation of /RestAPI and ImportTechnicians requests.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

93.3%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE