🔙 목록으로 돌아가기

CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus - Remote Code Execution

TitleZoho ManageEngine ServiceDesk Plus - Remote Code Execution
AuthorAdam Crosser,gy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patch or upgrade to a patched version of Zoho ManageEngine ServiceDesk Plus.
CVSS Score9.8
EPSS Score0.943
CVE IDCVE-2021-44077
CWE IDCWE-306
Shodan Queryhttp.title:"manageengine servicedesk plus"
Fofa Querytitle="manageengine servicedesk plus"
Tags cve2021 cve rce kev msf zoho manageengine zohocorp vkev vuln

🔍 Vulnerability Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution.

🌐 HTTP Request

GET /RestAPI/ImportTechnicians HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44077.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-44077.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A