Vulnerabilities in Zoho ManageEngine products being actively exploited
Attackers are known to be actively exploiting vulnerabilities in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus
Summary
Attackers are known to be actively exploiting vulnerabilities in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Two vulnerabilities in Zoho ManageEngine products, tracked as CVE-2021-37415 and CVE-2021-44077, are being actively exploited. CISA has added the vulnerabilities to their Known Exploited Vulnerabilities Catalog and issued a statement warning that the vulnerabilities are frequently targeted as an attack vector.
CVE-2021-37415 is rated critical (CVSS v3 9.8) and is an authentication bypass vulnerability in Zoho ManageEngine ServiceDesk Plus that allows a few REST-API URLs without authentication.
CVE-2021-44077 is rated critical (CVSS v3 9.8) and is a vulnerability in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus. The vulnerability is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration. An unauthorised attacker could exploit this vulnerability for remote code execution.
Remediation advice
Affected organisations are encouraged to review Zoho ManageEngine's security advisories (below) and apply the necessary updates.
Remediation steps
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 3 December 2021 2:21 pm