Zoho security update-CVE-2021-44077
NAME
Zoho Corp. – Multiple
- Platforms Affected:
Multiple - Risk Level:
high - CVE Type:
Improper authentication
DESCRIPTION
CVE-2021-44077 is an improper authentication vulnerability impacting multiple versions of Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus. A Metasploit module was observed in open source. Security researchers at the Cybersecurity and Infrastructure Security Agency (CISA) claimed the vulnerability was actively exploited in the wild to compromise unpatched systems.
CVSS Information:
- CVSS 2.0 SCORE: 7.5
- CVSS 3.0 SCORE: 9.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://us-cert[.]cisa[.]gov/ncas/current-activity/2021/12/01/cisa-adds-five-known-exploited-vulnerabilities-catalog
MITIGATION
Zoho addressed the vulnerability in a security advisory with updated versions.
- Reference Link:
https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-authentication-bypass-vulnerability-in-servicedesk-plus-versions-11138-and-above - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.