Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Dec 15, 2021

CVE-2021-37415

High
EPSS 92.0%CISA KEV
Zoho/ManageEngine ServiceDesk Plus (SDP)

Description

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication

EPSS — Exploit Probability

92.0%

Higher than 99.7% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2021-37415

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
92.0%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Dec 1, 2021

Added to KEV

Dec 1, 2021

Remediation Due

Dec 15, 2021

Affected Product

Zoho

ManageEngine ServiceDesk Plus (SDP)

View all Zoho CVEs