ZOHO ManageEngine Desktop Central MSP是美国卓豪(ZOHO)公司的一套面向MSP(管理服务提供商)的桌面机及移动设备管理软件。该软件可帮助MSP远程管理客户网络中的桌面机、服务器以及移动设备,并为各种规模的企业提供差异化的管理服务。 Zoho ManageEngine Desktop Central MSP存在授权问题漏洞,此漏洞的存在是由于在处理身份验证请求时出现错误。远程攻击者可利用该漏洞可以绕过身份验证过程并在桌面中心MSP服务器上执行任意代码。该漏洞允许远程攻击
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Zoho ManageEngine Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44515.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-44833 | OpenSearch Web browser 安全漏洞 | |
| CVE-2021-41805 | Hashicorp HashiCorp Consul 安全漏洞 |
No comments yet