CVE-2021-44077

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
zohocorpmanageengine_servicedesk_plus
11.1:11138
zohocorpmanageengine_servicedesk_plus
11.1:11139
zohocorpmanageengine_servicedesk_plus
11.1:11140
zohocorpmanageengine_servicedesk_plus
11.1:11141
zohocorpmanageengine_servicedesk_plus
11.1:11142
zohocorpmanageengine_servicedesk_plus
11.1:11143
zohocorpmanageengine_servicedesk_plus
11.1:11144
zohocorpmanageengine_servicedesk_plus
11.1:11145
zohocorpmanageengine_servicedesk_plus
11.2:11200
zohocorpmanageengine_servicedesk_plus
11.2:11201
zohocorpmanageengine_servicedesk_plus
11.2:11202
zohocorpmanageengine_servicedesk_plus
11.2:11203
zohocorpmanageengine_servicedesk_plus
11.2:11204
zohocorpmanageengine_servicedesk_plus
11.2:11205
zohocorpmanageengine_servicedesk_plus
11.2:11206
zohocorpmanageengine_servicedesk_plus
11.2:11207
zohocorpmanageengine_servicedesk_plus
11.2:11208
zohocorpmanageengine_servicedesk_plus
11.2:11209
zohocorpmanageengine_servicedesk_plus
11.2:11210
zohocorpmanageengine_servicedesk_plus
11.2:11211
zohocorpmanageengine_servicedesk_plus
11.3:11300
zohocorpmanageengine_servicedesk_plus
11.3:11301
zohocorpmanageengine_servicedesk_plus
11.3:11302
zohocorpmanageengine_servicedesk_plus
11.3:11303
zohocorpmanageengine_servicedesk_plus
11.3:11304
zohocorpmanageengine_servicedesk_plus
11.3:11305
zohocorpmanageengine_servicedesk_plus_msp
𝑥
≤ 10.5
zohocorpmanageengine_servicedesk_plus_msp
10.5:10500
zohocorpmanageengine_servicedesk_plus_msp
10.5:10501
zohocorpmanageengine_servicedesk_plus_msp
10.5:10502
zohocorpmanageengine_servicedesk_plus_msp
10.5:10503
zohocorpmanageengine_servicedesk_plus_msp
10.5:10504
zohocorpmanageengine_servicedesk_plus_msp
10.5:10505
zohocorpmanageengine_servicedesk_plus_msp
10.5:10506
zohocorpmanageengine_servicedesk_plus_msp
10.5:10507
zohocorpmanageengine_servicedesk_plus_msp
10.5:10508
zohocorpmanageengine_servicedesk_plus_msp
10.5:10509
zohocorpmanageengine_servicedesk_plus_msp
10.5:10510
zohocorpmanageengine_servicedesk_plus_msp
10.5:10511
zohocorpmanageengine_servicedesk_plus_msp
10.5:10512
zohocorpmanageengine_servicedesk_plus_msp
10.5:10513
zohocorpmanageengine_servicedesk_plus_msp
10.5:10514
zohocorpmanageengine_servicedesk_plus_msp
10.5:10515
zohocorpmanageengine_servicedesk_plus_msp
10.5:10516
zohocorpmanageengine_servicedesk_plus_msp
10.5:10517
zohocorpmanageengine_servicedesk_plus_msp
10.5:10518
zohocorpmanageengine_servicedesk_plus_msp
10.5:10519
zohocorpmanageengine_servicedesk_plus_msp
10.5:10520
zohocorpmanageengine_servicedesk_plus_msp
10.5:10521
zohocorpmanageengine_servicedesk_plus_msp
10.5:10522
zohocorpmanageengine_servicedesk_plus_msp
10.5:10523
zohocorpmanageengine_servicedesk_plus_msp
10.5:10524
zohocorpmanageengine_servicedesk_plus_msp
10.5:10525
zohocorpmanageengine_servicedesk_plus_msp
10.5:10526
zohocorpmanageengine_servicedesk_plus_msp
10.5:10527
zohocorpmanageengine_servicedesk_plus_msp
10.5:10528
zohocorpmanageengine_servicedesk_plus_msp
10.5:10529
zohocorpmanageengine_supportcenter_plus
𝑥
≤ 11.0
zohocorpmanageengine_supportcenter_plus
11.0:11000
zohocorpmanageengine_supportcenter_plus
11.0:11001
zohocorpmanageengine_supportcenter_plus
11.0:11002
zohocorpmanageengine_supportcenter_plus
11.0:11003
zohocorpmanageengine_supportcenter_plus
11.0:11004
zohocorpmanageengine_supportcenter_plus
11.0:11005
zohocorpmanageengine_supportcenter_plus
11.0:11006
zohocorpmanageengine_supportcenter_plus
11.0:11007
zohocorpmanageengine_supportcenter_plus
11.0:11008
zohocorpmanageengine_supportcenter_plus
11.0:11009
zohocorpmanageengine_supportcenter_plus
11.0:11010
zohocorpmanageengine_supportcenter_plus
11.0:11011
zohocorpmanageengine_supportcenter_plus
11.0:11012
zohocorpmanageengine_supportcenter_plus
11.0:11013
𝑥
= Vulnerable software versions
References