HTTP: Zoho ManageEngine ServiceDesk Plus Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Zoho ManageEngine. A successful attack can lead to arbitrary code execution.

Extended Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

Affected Products

Zohocorp manageengine_servicedesk_plus

Short Name
HTTP:CTS:ZOHO-MNGNENG-SDP-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2021-44077 Code Execution ManageEngine Plus Remote ServiceDesk Zoho
Release Date
12/03/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Zohocorp

CVSS Score

7.5

Found a potential security threat?