Skip to content
COOEY

EXPOSURES › CVE-2021-37415

CVE-2021-37415

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-37415 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedauth-bypass

An authentication bypass in Zoho ManageEngine ServiceDesk Plus allowed unauthenticated access to REST-API URLs, enabling attackers to bypass login and potentially access sensitive IT service data.

The vulnerability allowed attackers to access REST-API endpoints without authentication, exposing sensitive IT service management data and potentially enabling further attacks. DIB organizations using this product must patch immediately and monitor for unauthorized API access. This is a known, unpatched vulnerability that was actively exploited in the wild.

Shame score — A known authentication bypass vulnerability remained unpatched and was actively exploited in the wild, allowing unauthenticated access to sensitive IT service data.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.