CVE-2021-44515
Summary
| CVE | CVE-2021-44515 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-12 05:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. |
Risk And Classification
EPSS: 0.998670000 probability, percentile 0.999620000 (date 2026-07-22)
CISA KEV: Listed on 2021-12-10; due 2021-12-24; ransomware use Unknown
Problem Types: NVD-CWE-noinfo
CISA Known Exploited Vulnerability
| Vendor | Zoho |
|---|---|
| Product | Desktop Central |
| Name | Zoho Desktop Central Authentication Bypass Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2021-44515 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zohocorp | Manageengine Desktop Central | All | All | All | All |
| Application | Zohocorp | Manageengine Desktop Central | All | All | All | All |
| Application | Zohocorp | Manageengine Desktop Central | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| An authentication bypass vulnerability identified and fixed in Desktop Central and Desktop Central MSP | CONFIRM | pitstop.manageengine.com | |
| CISA Adds Thirteen Known Exploited Vulnerabilities to Catalog | CISA | MISC | www.cisa.gov | |
| Authentication Bypass using Filter Configuration | ManageEngine | CONFIRM | www.manageengine.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.