QID 730298
Date Published: 2021-12-20
QID 730298: Zoho ManageEngine Desktop Central and Desktop Central MSP Authentication Bypass Vulnerability (Unauthenticated Check)
Zoho ManageEngine Desktop Central is an integrated desktop and mobile device management software that helps in managing the servers, laptops, desktops, smart phones and tablets from a central point.
An authentication bypass vulnerability in ManageEngine Desktop Central that could result in remote code execution.
Affected Versions:
For Enterprise:
Builds 10.1.2127.17 and below, upgrade to 10.1.2127.18
Builds 10.1.2128.0 to 10.1.2137.2, upgrade to 10.1.2137.3
For MSP:
Builds 10.1.2127.17 and below, upgrade to 10.1.2127.18
Builds 10.1.2128.0 to 10.1.2137.2, upgrade to 10.1.2137.3
QID Detection Logic:(Unauthenticated)
This QID sends a GET request to /configurations.do to retrieve the build number of the Desktop Central on the remote target.
If exploited, the attackers can gain unauthorized access to the product by sending a specially crafted request leading to remote code execution.
- ManageEngine Desktop Central Advisory -
www.manageengine.com/products/desktop-central/cve-2021-44515-authentication-bypass-filter-configuration.html
CVEs related to QID 730298
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ManageEngine Desktop Central and MSP |
|