CVE-2021-37415
KEVlargeAuthentication Bypass in Zoho ManageEngine ServiceDesk Plus REST API
CISA: Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
CVE-2021-37415 is a missing-authentication flaw (CWE-306) in Zoho ManageEngine ServiceDesk Plus, an on-premises IT help desk and asset management platform. In builds before 11302, certain REST-API URLs can be reached without any authentication, so an unauthenticated attacker who can reach the service desk's HTTP interface can invoke those endpoints directly. Successful abuse grants access to whatever those REST endpoints expose, bypassing the product's normal login controls; CISA lists it on the Known Exploited Vulnerabilities catalog, and required action is applying vendor updates. Any organization running ServiceDesk Plus at a build earlier than 11302 is affected, with exposure concentrated on instances whose web/REST interfaces are reachable from the internet or untrusted networks. No public proof-of-concept is known, but CISA's KEV listing (added 2021-12-01) and an EPSS of 99.8% indicate active exploitation pressure.
What to do: Upgrade ManageEngine ServiceDesk Plus to build 11302 or later per the vendor's instructions, as required by CISA's KEV listing. Until patched, restrict network access to the ServiceDesk Plus web/REST interfaces (reverse proxy, firewall, or VPN) and review access logs for unauthenticated requests to REST-API endpoints.
| Zoho ManageEngine ServiceDesk Plus (SDP) | All builds before 11302 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
- Affected
- Zoho ManageEngine ServiceDesk Plus (SDP)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zohocorp
- Products
- manageengine servicedesk plus
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H