CVE-2021-44077
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 94% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-306
מוצרים מושפעים
zohocorp: manageengine servicedesk plus; zohocorp: manageengine servicedesk plus msp; zohocorp: manageengine supportcenter plus
קישורים
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-a… PatchVendor Advisory
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-f… Vendor Advisory
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-f… Vendor Advisory
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-f… Vendor Advisory
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-a… PatchVendor Advisory
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-f… Vendor Advisory
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-f… Vendor Advisory
- https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-f… Vendor Advisory
- http://packetstormsecurity.com/files/165400/ManageEngine-ServiceDesk-Plus-Remo… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/165400/ManageEngine-ServiceDesk-Plus-Remo… ExploitThird Party AdvisoryVDB Entry