← Back to CVE List
Vulnerability Intelligence Report
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

CVE-2021-44077

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:93.51%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-306 ↗CWE-306 Missing Authentication for Critical Function

Affected Products & Versions

Vendor Product Affected Versions
zohocorp manageengine_servicedesk_plus 11.1, 11.2, 11.3
zohocorp manageengine_servicedesk_plus_msp 10.5
zohocorp manageengine_supportcenter_plus 11.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
93.514%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-11-20T00:00:00
Published2021-11-29T03:17:45
Last Updated2025-10-21T23:25:24

LINK COPIED TO CLIPBOARD