{"api_version":"1","generated_at":"2026-07-23T14:04:28+00:00","cve":"CVE-2021-44515","urls":{"html":"https://cve.report/CVE-2021-44515","api":"https://cve.report/api/cve/CVE-2021-44515.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-44515","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-44515"},"summary":{"title":"CVE-2021-44515","description":"Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-12-12 05:15:00","updated_at":"2022-07-12 17:42:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://pitstop.manageengine.com/portal/en/community/topic/an-authentication-bypass-vulnerability-identified-and-fixed-in-desktop-central-and-desktop-central-msp","name":"https://pitstop.manageengine.com/portal/en/community/topic/an-authentication-bypass-vulnerability-identified-and-fixed-in-desktop-central-and-desktop-central-msp","refsource":"CONFIRM","tags":[],"title":"An authentication bypass vulnerability identified and fixed in Desktop Central and Desktop Central MSP","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/uscert/ncas/current-activity/2021/12/10/cisa-adds-thirteen-known-exploited-vulnerabilities-catalog","name":"https://www.cisa.gov/uscert/ncas/current-activity/2021/12/10/cisa-adds-thirteen-known-exploited-vulnerabilities-catalog","refsource":"MISC","tags":[],"title":"CISA Adds Thirteen Known Exploited Vulnerabilities to Catalog | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.manageengine.com/products/desktop-central/cve-2021-44515-authentication-bypass-filter-configuration.html","name":"https://www.manageengine.com/products/desktop-central/cve-2021-44515-authentication-bypass-filter-configuration.html","refsource":"CONFIRM","tags":[],"title":"Authentication Bypass using Filter Configuration | ManageEngine","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-44515","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44515","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"44515","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zohocorp","cpe5":"manageengine_desktop_central","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"44515","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zohocorp","cpe5":"manageengine_desktop_central","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"managed_service_providers","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"44515","vulnerable":"1","versionEndIncluding":"10.1.2137.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zohocorp","cpe5":"manageengine_desktop_central","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2021","cve_id":"44515","cve":"CVE-2021-44515","vendorProject":"Zoho","product":"Desktop Central","vulnerabilityName":"Zoho Desktop Central Authentication Bypass Vulnerability","dateAdded":"2021-12-10","shortDescription":"Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2021-12-24","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-44515","cwes":"","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:16"},"epss":{"cve_year":"2021","cve_id":"44515","cve":"CVE-2021-44515","epss":"0.998670000","percentile":"0.999620000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[{"cve":"CVE-2021-44515","qid":"376138","title":"Zoho ManageEngine Desktop Central and Desktop Central MSP Authentication Bypass Vulnerability"},{"cve":"CVE-2021-44515","qid":"730298","title":"Zoho ManageEngine Desktop Central and Desktop Central MSP Authentication Bypass Vulnerability (Unauthenticated Check)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-44515","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://pitstop.manageengine.com/portal/en/community/topic/an-authentication-bypass-vulnerability-identified-and-fixed-in-desktop-central-and-desktop-central-msp","url":"https://pitstop.manageengine.com/portal/en/community/topic/an-authentication-bypass-vulnerability-identified-and-fixed-in-desktop-central-and-desktop-central-msp"},{"refsource":"CONFIRM","name":"https://www.manageengine.com/products/desktop-central/cve-2021-44515-authentication-bypass-filter-configuration.html","url":"https://www.manageengine.com/products/desktop-central/cve-2021-44515-authentication-bypass-filter-configuration.html"},{"refsource":"MISC","name":"https://www.cisa.gov/uscert/ncas/current-activity/2021/12/10/cisa-adds-thirteen-known-exploited-vulnerabilities-catalog","url":"https://www.cisa.gov/uscert/ncas/current-activity/2021/12/10/cisa-adds-thirteen-known-exploited-vulnerabilities-catalog"}]}},"nvd":{"publishedDate":"2021-12-12 05:15:00","lastModifiedDate":"2022-07-12 17:42:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:managed_service_providers:*:*:*","versionStartIncluding":"10.1.2128.0","versionEndExcluding":"10.1.2137.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:managed_service_providers:*:*:*","versionEndExcluding":"10.1.2127.18","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"10.1.2128.0","versionEndIncluding":"10.1.2137.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:enterprise:*:*:*","versionEndExcluding":"10.1.2127.18","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"44515","Ordinal":"222272","Title":"CVE-2021-44515","CVE":"CVE-2021-44515","Year":"2021"},"notes":[]}}}