CVE-2021-37415

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
zohocorpmanageengine_servicedesk_plus
11.0:11005
zohocorpmanageengine_servicedesk_plus
11.0:11006
zohocorpmanageengine_servicedesk_plus
11.0:11007
zohocorpmanageengine_servicedesk_plus
11.0:11008
zohocorpmanageengine_servicedesk_plus
11.0:11009
zohocorpmanageengine_servicedesk_plus
11.0:11010
zohocorpmanageengine_servicedesk_plus
11.0:11011
zohocorpmanageengine_servicedesk_plus
11.1
zohocorpmanageengine_servicedesk_plus
11.1:11100
zohocorpmanageengine_servicedesk_plus
11.1:11101
zohocorpmanageengine_servicedesk_plus
11.1:11102
zohocorpmanageengine_servicedesk_plus
11.1:11103
zohocorpmanageengine_servicedesk_plus
11.1:11104
zohocorpmanageengine_servicedesk_plus
11.1:11105
zohocorpmanageengine_servicedesk_plus
11.1:11106
zohocorpmanageengine_servicedesk_plus
11.1:11107
zohocorpmanageengine_servicedesk_plus
11.1:11108
zohocorpmanageengine_servicedesk_plus
11.1:11109
zohocorpmanageengine_servicedesk_plus
11.1:11110
zohocorpmanageengine_servicedesk_plus
11.1:11111
zohocorpmanageengine_servicedesk_plus
11.1:11112
zohocorpmanageengine_servicedesk_plus
11.1:11113
zohocorpmanageengine_servicedesk_plus
11.1:11114
zohocorpmanageengine_servicedesk_plus
11.1:11115
zohocorpmanageengine_servicedesk_plus
11.1:11116
zohocorpmanageengine_servicedesk_plus
11.1:11117
zohocorpmanageengine_servicedesk_plus
11.1:11118
zohocorpmanageengine_servicedesk_plus
11.1:11119
zohocorpmanageengine_servicedesk_plus
11.1:11120
zohocorpmanageengine_servicedesk_plus
11.1:11121
zohocorpmanageengine_servicedesk_plus
11.1:11122
zohocorpmanageengine_servicedesk_plus
11.1:11123
zohocorpmanageengine_servicedesk_plus
11.1:11124
zohocorpmanageengine_servicedesk_plus
11.1:11125
zohocorpmanageengine_servicedesk_plus
11.1:11126
zohocorpmanageengine_servicedesk_plus
11.1:11127
zohocorpmanageengine_servicedesk_plus
11.1:11128
zohocorpmanageengine_servicedesk_plus
11.1:11129
zohocorpmanageengine_servicedesk_plus
11.1:11130
zohocorpmanageengine_servicedesk_plus
11.1:11131
zohocorpmanageengine_servicedesk_plus
11.1:11132
zohocorpmanageengine_servicedesk_plus
11.1:11133
zohocorpmanageengine_servicedesk_plus
11.1:11134
zohocorpmanageengine_servicedesk_plus
11.1:11135
zohocorpmanageengine_servicedesk_plus
11.1:11136
zohocorpmanageengine_servicedesk_plus
11.1:11137
zohocorpmanageengine_servicedesk_plus
11.1:11138
zohocorpmanageengine_servicedesk_plus
11.1:11139
zohocorpmanageengine_servicedesk_plus
11.1:11140
zohocorpmanageengine_servicedesk_plus
11.1:11141
zohocorpmanageengine_servicedesk_plus
11.1:11142
zohocorpmanageengine_servicedesk_plus
11.1:11143
zohocorpmanageengine_servicedesk_plus
11.1:11144
zohocorpmanageengine_servicedesk_plus
11.2
zohocorpmanageengine_servicedesk_plus
11.2:11200
zohocorpmanageengine_servicedesk_plus
11.2:11201
zohocorpmanageengine_servicedesk_plus
11.2:11202
zohocorpmanageengine_servicedesk_plus
11.2:11203
zohocorpmanageengine_servicedesk_plus
11.2:11204
zohocorpmanageengine_servicedesk_plus
11.2:11205
zohocorpmanageengine_servicedesk_plus
11.2:11206
zohocorpmanageengine_servicedesk_plus
11.2:11207
zohocorpmanageengine_servicedesk_plus
11.3
zohocorpmanageengine_servicedesk_plus
11.3:11300
zohocorpmanageengine_servicedesk_plus
11.3:11301
𝑥
= Vulnerable software versions