CVE-2021-44077

Description from NVD

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

Information Acquisition Date:2022-06-06T14:54Z
CVSS 2.0: 7.5 HIGH CVSS 3.x: 9.8 CRITICAL

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

▼ CVSS2 Vec AV:N/AC:L/Au:N/C:P/I:P/A:P

NVD References

 https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vulnerability-in-servicedesk-plus-versions-up-to-11305-22-11-2021
     source:MISC
     tags:Vendor Advisory    
 https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-authentication-bypass-vulnerability-in-servicedesk-plus-versions-11138-and-above
     source:MISC
     tags:Patch    Vendor Advisory    
 https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vulnerability-in-servicedesk-plus-msp-versions-10527-till-10529
     source:MISC
     tags:Vendor Advisory    
 https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44077-unauthenticated-rce-vulnerability-in-supportcenter-plus-versions-11012-and-11013
     source:MISC
     tags:Vendor Advisory    
 http://packetstormsecurity.com/files/165400/ManageEngine-ServiceDesk-Plus-Remote-Code-Execution.html
     source:MISC
     tags:Exploit    Third Party Advisory    VDB Entry    

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag:



List of frequently cited URLs

URLNum of Times Referred to
http://patrowl.io205
https://www.lunasec.io/docs/blog/log4j-zero-day176
https://cvetrends.com55
https://lists.astaro.com/ASGV9-IPS-rules.html#019
https://ift.tt/3xQ0DBZ11
https://us-cert.cisa.gov/ncas/alerts/aa21-336a4
https://www.helpnetsecurity.com/2021/12/03/cve-2021-44077/?...4
https://bit.ly/3qDCg7n3
https://github.com/horizon3ai/CVE-2021-440773
http://go.usa.gov/xeVYA3
https://twitter.com/CISAgov/status/14665420160331366473
https://xz.aliyun.com/3
https://ipssignatures.appspot.com/?cve=CVE-2021-440773

Information from Twitter

User URL Info Source Date
jc_vazquez https://bit.ly/3x9pD79 Source jc_vazquez       1533628820208508928 2022/06/06
jc_vazquez https://twitter.com/jc_vazquez/status/1533628820208508928/p... Source jc_vazquez       1533628820208508928 2022/06/06
NeobeePaul https://us-cert.cisa.gov/ncas/alerts/aa21-336a Source NeobeePaul       1533762302863757312 2022/06/06
TheDFIRReport https://thedfirreport.com/2022/06/06/will-the-real-msiexec-... Source TheDFIRReport    1533771110336036865 2022/06/06
CVEtrends https://cvetrends.com Source CVEtrends        1533795856155131905 2022/06/06
tribal_sec https://thedfirreport.com/2022/06/06/will-the-real-msiexec-... Source tribal_sec       1534553502856388608 2022/06/09
tribal_sec https://twitter.com/tribal_sec/status/1534553502856388608/p... Source tribal_sec       1534553502856388608 2022/06/09
Cyber_Cave_sa https://twitter.com/Cyber_Cave_sa/status/153734686836312064... Source Cyber_Cave_sa    1537346868363120641 2022/06/16
Cyber_Cave_sa https://twitter.com/Cyber_Cave_sa/status/153734864957067264... Source Cyber_Cave_sa    1537348649570672641 2022/06/16
a3sec https://hubs.ly/Q01g3hGf0 Source a3sec            1542946137488883712 2022/07/02

List of frequently cited URLs

URLNum of Times Referred to
patrowl.io205
www.lunasec.io176
cvetrends.com55
lists.astaro.com19
ift.tt11
us-cert.cisa.gov4
www.helpnetsecurity.com4
bit.ly3
github.com3
go.usa.gov3
twitter.com3
xz.aliyun.com3
ipssignatures.appspot.com3

Information from Twitter

User URL Info Source
jc_vazquez bit.ly Show Tweet
jc_vazquez twitter.com Show Tweet
NeobeePaul us-cert.cisa.gov Show Tweet
TheDFIRReport thedfirreport.com Show Tweet
CVEtrends cvetrends.com Show Tweet
tribal_sec thedfirreport.com Show Tweet
tribal_sec twitter.com Show Tweet
Cyber_Cave_sa twitter.com Show Tweet
Cyber_Cave_sa twitter.com Show Tweet
a3sec hubs.ly Show Tweet

GitHub Search Results: Up to 10
NameURL
No Data

GitHub Search Results: Up to 10
NameURL
No Data

2022/07/02 Score : 1
Added Har-sia Database : 2021/11/29
Last Modified : 2022/07/02
Highest Scored Date : 2021/12/03
Highest Score : 103