S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-44515 Scanner

CVE-2021-44515 scanner - Authentication Bypass vulnerability in Zoho ManageEngine Desktop Central

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-44515
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zoho ManageEngine Desktop Central is an advanced remote desktop and device management software designed for IT professionals in enterprises and Managed Service Providers (MSPs). The central management system helps administrators to automate their desktop management tasks, including software deployment, patch management, inventory management, and mobile device management. It streamlines IT operations, secures endpoints, and helps businesses to remain compliant.

Recently, a critical security vulnerability was found in Zoho ManageEngine Desktop Central. The CVE-2021-44515 vulnerability allows an attacker to bypass the authentication process, leading to remote code execution on the server. According to reports, this vulnerability has been actively exploited in the wild since December 2021 by a threat actor group called Blue Mockingbird.

When exploited, the CVE-2021-44515 vulnerability can allow attackers to gain unauthorized access to the Zoho ManageEngine Desktop Central server. This can be used to steal or modify sensitive data, install malware, or launch attacks on the affected network and connected devices. The potential impact of such an attack can be severe and lead to data breaches, financial losses, and reputational damage.

By using the pro features of the s4e.io platform, readers of this article can easily identify any vulnerabilities that may exist in their digital assets and take appropriate measures. With its advanced scanning and reporting capabilities, s4e.io can provide a comprehensive assessment of an organization's digital assets to identify and remediate vulnerabilities and security weaknesses. Protect your business from cyber threats by subscribing to s4e.io today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, follow these precautions:

  • Upgrade to the latest version if your Zoho ManageEngine Desktop Central software is running on a version affected by the vulnerability.
  • Implement multi-factor authentication (MFA) in your Zoho ManageEngine Desktop Central deployment.
  • Restrict access to the Zoho ManageEngine Desktop Central server and its management console using firewall rules and access control lists (ACLs).
  • Review and validate your system logs and traffic for any suspicious activities or patterns.
  • Deploy an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) to monitor and block malicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-44515 scanner - Authentication Bypass vulnerability in Zoho ManageEngine Desktop Central S4E