S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-44077 Scanner

CVE-2021-44077 scanner - Remote Code Execution (RCE) vulnerability in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-44077
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus are powerful tools for businesses to streamline their IT ticketing and customer support processes. These products allow companies to efficiently manage their customer support requests, assign tasks to staff, track progress, and analyze data to identify areas for improvement. With their user-friendly interface and extensive customization options, the ServiceDesk Plus suite has become a popular choice for businesses of all sizes.

Recently, a critical vulnerability, CVE-2021-44077, was discovered in these products. This vulnerability allows remote attackers to execute arbitrary code without authentication, and it is related to the RestAPI URLs in a servlet and ImportTechnicians in the Struts configuration. Attackers can exploit this vulnerability to gain access to sensitive data and take control of the affected systems.

If this vulnerability is exploited, it can lead to catastrophic consequences for businesses. Attackers can steal sensitive data or exfiltrate critical information, leading to financial loss and reputational damage. Additionally, attackers can deploy malware or ransomware on the affected systems, causing downtime and disrupting operations.

Thanks to the pro features of s4e.io, businesses can easily and quickly learn about vulnerabilities in their digital assets. With its advanced penetration testing tools and real-time alerts, businesses can stay one step ahead of attackers and protect their network from potential threats. Don't wait until it's too late – secure your systems today with s4e.io.

 

REFERENCES

Solution Advice

To prevent this vulnerability from being exploited, businesses must take immediate measures to secure their systems. The following precautions can be taken:

  • Update affected systems with the latest security patches and fixes.
  • Implement security best practices to secure their IT infrastructure and networks.
  • Monitor their systems for suspicious activity and anomalies.
  • Conduct regular security audits and risk assessments to identify potential vulnerabilities.
  • Educate their staff on cybersecurity best practices and keep them up to date with the latest threats and trends.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.