ZeroHour

CVE-2021-37415

KEVlarge

Authentication Bypass in Zoho ManageEngine ServiceDesk Plus REST API

CISA: Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-37415 is a missing-authentication flaw (CWE-306) in Zoho ManageEngine ServiceDesk Plus, an on-premises IT help desk and asset management platform. In builds before 11302, certain REST-API URLs can be reached without any authentication, so an unauthenticated attacker who can reach the service desk's HTTP interface can invoke those endpoints directly. Successful abuse grants access to whatever those REST endpoints expose, bypassing the product's normal login controls; CISA lists it on the Known Exploited Vulnerabilities catalog, and required action is applying vendor updates. Any organization running ServiceDesk Plus at a build earlier than 11302 is affected, with exposure concentrated on instances whose web/REST interfaces are reachable from the internet or untrusted networks. No public proof-of-concept is known, but CISA's KEV listing (added 2021-12-01) and an EPSS of 99.8% indicate active exploitation pressure.

What to do: Upgrade ManageEngine ServiceDesk Plus to build 11302 or later per the vendor's instructions, as required by CISA's KEV listing. Until patched, restrict network access to the ServiceDesk Plus web/REST interfaces (reverse proxy, firewall, or VPN) and review access logs for unauthenticated requests to REST-API endpoints.

Affected
Zoho ManageEngine ServiceDesk Plus (SDP)All builds before 11302
Estimated exposure
largetens of thousands of on-premises ServiceDesk Plus deployments, a subset internet-exposed — ServiceDesk Plus is a widely deployed mid-market/enterprise help-desk product with a broad installed base of on-prem instances, and public internet scans routinely find exposed ManageEngine ServiceDesk servers, so deployments before build…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

CISA Known Exploited Vulnerability
Affected
Zoho ManageEngine ServiceDesk Plus (SDP)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zohocorp
Products
manageengine servicedesk plus
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news